6.1

CVE-2022-28977

HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.0 Update-
LiferayDigital Experience Platform Version7.0 Updatefix_pack_100
LiferayDigital Experience Platform Version7.0 Updatefix_pack_101
LiferayDigital Experience Platform Version7.0 Updatefix_pack_91
LiferayDigital Experience Platform Version7.0 Updatefix_pack_92
LiferayDigital Experience Platform Version7.0 Updatefix_pack_93
LiferayDigital Experience Platform Version7.0 Updatefix_pack_94
LiferayDigital Experience Platform Version7.0 Updatefix_pack_95
LiferayDigital Experience Platform Version7.0 Updatefix_pack_96
LiferayDigital Experience Platform Version7.0 Updatefix_pack_97
LiferayDigital Experience Platform Version7.0 Updatefix_pack_98
LiferayDigital Experience Platform Version7.0 Updatefix_pack_99
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_17
LiferayDigital Experience Platform Version7.1 Updatefix_pack_18
LiferayDigital Experience Platform Version7.1 Updatefix_pack_19
LiferayDigital Experience Platform Version7.1 Updatefix_pack_20
LiferayDigital Experience Platform Version7.1 Updatefix_pack_21
LiferayDigital Experience Platform Version7.1 Updatefix_pack_22
LiferayDigital Experience Platform Version7.1 Updatefix_pack_23
LiferayDigital Experience Platform Version7.1 Updatefix_pack_24
LiferayDigital Experience Platform Version7.1 Updatefix_pack_25
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_12
LiferayDigital Experience Platform Version7.2 Updatefix_pack_13
LiferayDigital Experience Platform Version7.2 Updatefix_pack_14
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDxp Version7.3 Update-
LiferayDxp Version7.3 Updatesp1
LiferayDxp Version7.3 Updatesp2
LiferayLiferay Portal Version >= 7.3.1 < 7.4.3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.417
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.