Description
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Remediation
References
Related Vulnerabilities
WordPress Plugin Platinum SEO Pack Cross-Site Scripting (1.3.7)
MODX CVE-2017-7323 Vulnerability (CVE-2017-7323)
WordPress Plugin WP Super Cache Cross-Site Scripting (1.7.2)
Zope Web Application Server Other Vulnerability (CVE-2001-1278)
Python Credentials Management Errors Vulnerability (CVE-2019-10160)