First published: Thu Feb 21 2013(Updated: )
The GateIn Portal Export / Import Gadget allows an export zip to be uploaded and imported to a site without authentication. A remote attacker could use this flaw to modify the content of a site, remove the site or modify access controls applied to portlets in the site.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Portal Platform | =5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.