VYPR
Unrated severityNVD Advisory· Published May 29, 2014· Updated Jun 17, 2026

CVE-2014-3416

CVE-2014-3416

Description

uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.

Affected products

1
  • cpe:2.3:a:jasig:uportal:*:*:*:*:*:*:*:*
    Range: <=4.0.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.