CST-7211 User can change password without current password

Description

In Liferay Portal 7.2.0 and earlier, users can update their password via JSONWS without supplying their current password. An attacker can exploit this to modify a user password by leveraging XSS, session hijacking, an unattended workstation or other vectors.

Severity

Severity 2

Fixed Version(s)

Publication date: Mon, 02 Mar 2020 07:21:00 +0000