CVE-2023-33949

Source
https://cve.org/CVERecord?id=CVE-2023-33949
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-33949.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-33949
Aliases
Published
2023-05-24T17:15:09.933Z
Modified
2026-05-15T12:04:50.883478435Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property company.security.strangers.verify should be set to true.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_FIELD",
            "vendor_product": "liferay:digital_experience_platform",
            "extracted_events": [
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages