NA

CVE-2024-26268

Published: 20/02/2024 Updated: 20/02/2024

Vulnerability Summary

User enumeration vulnerability in Liferay Portal 7.2.0 up to and including 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote malicious users to determine if an account exist in the application by comparing the request's response time.