Liferay Portal Vulnerable to IDOR via audit events
Moderate severity
GitHub Reviewed
Published
Sep 30, 2025
to the GitHub Advisory Database
•
Updated Oct 1, 2025
Description
Published by the National Vulnerability Database
Sep 30, 2025
Published to the GitHub Advisory Database
Sep 30, 2025
Reviewed
Oct 1, 2025
Last updated
Oct 1, 2025
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from one virtual instance to view the audit events from a different virtual instance via the _com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId parameter.
References