Description
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Remediation
References
Related Vulnerabilities
WordPress Plugin Relevant-Related Posts by BestWebSoft Cross-Site Scripting (1.1.9)
WordPress Plugin SiteGround Security Security Bypass (1.2.5)
WordPress Plugin Royal Gallery Cross-Site Scripting (2.0)
WordPress Plugin Email posts to subscribers Multiple Vulnerabilities (2.0)
WordPress Plugin On Page SEO + Social Live Chat (Formerly OPS) Cross-Site Scripting (1.0.1)