CVE-2023-47798 MEDIUM

CVE-2023-47798

Vendor Liferay
Product Portal
Weakness CWE-384 · Session fixation
Published February 8, 2024
Last update May 15, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Key dates

02Disclosure timeline

February 8, 2024 CVE published
May 15, 2025 Record updated