cvedb.io
CVE-2022-38512
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2022-09-22T01:15:11.897 · Last modified 2026-06-17T04:56:46.617

Summary

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.

Affected products

liferay — dxp

Does this affect you?

Add your gear to cvedb and we'll alert you only when liferay ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.