Description
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
Remediation
References
Related Vulnerabilities
WordPress 2.3.2 Post Edit Unauthorized Access Vulnerability (0.7 - 2.3.2)
WordPress Plugin Front End Upload 'upload.php' Arbitrary File Upload (0.5.3)
WordPress 3.9.1 Multiple Vulnerabilities (3.9 - 3.9.1)
WordPress Plugin Seo Optimized Images Malicious Code (2.1.2)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.9.7)