Description
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2024-21131 Vulnerability (CVE-2024-21131)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5447)
WordPress Plugin AgentPress Broker Listings Cross-Site Scripting (1.0)
Django Improper Neutralization of Script in Attributes in a Web Page Vulnerability (CVE-2026-15920)