Description
In Liferay Portal 7.1.3 and possibly earlier unsupported versions, it is possible to enumerate the users in the portal through the forget password functionality.
Severity
Severity 2
Fixed Version(s)
- March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page.
Publication date: Thu, 05 Mar 2020 07:35:00 +0000