CST-7211 User can change password without current password

Description

In Liferay Portal 7.2.0 and earlier, users can update their password via JSONWS without supplying their current password. An attacker can exploit this to modify a user password by leveraging XSS, session hijacking, an unattended workstation or other vectors.

Severity

Severity 2

Fixed Version(s)

Publication date: Mon, 02 Mar 2020 07:21:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.