CVE-2021-33321

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
03/08/2021
Last modified:
11/08/2021

Description

Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:liferay:dxp:*:*:*:*:*:*:*:* 7.3 (excluding)
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* 6.2.3 (including) 7.3.3 (excluding)