An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://portal.liferay.dev/learn/security/known-vulnerabilities | not applicable |