VYPR
Unrated severityNVD Advisory· Published May 29, 2014· Updated Jun 17, 2026

CVE-2014-3417

CVE-2014-3417

Description

uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.

Affected products

1
  • cpe:2.3:a:jasig:uportal:*:*:*:*:*:*:*:*
    Range: <=4.0.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.