6.1

CVE-2023-5190

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.

Data is provided by the National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.4 Updateupdate45
LiferayDigital Experience Platform Version7.4 Updateupdate46
LiferayDigital Experience Platform Version7.4 Updateupdate47
LiferayDigital Experience Platform Version7.4 Updateupdate48
LiferayDigital Experience Platform Version7.4 Updateupdate49
LiferayDigital Experience Platform Version7.4 Updateupdate50
LiferayDigital Experience Platform Version7.4 Updateupdate51
LiferayDigital Experience Platform Version7.4 Updateupdate52
LiferayDigital Experience Platform Version7.4 Updateupdate53
LiferayDigital Experience Platform Version7.4 Updateupdate54
LiferayDigital Experience Platform Version7.4 Updateupdate55
LiferayDigital Experience Platform Version7.4 Updateupdate56
LiferayDigital Experience Platform Version7.4 Updateupdate57
LiferayDigital Experience Platform Version7.4 Updateupdate58
LiferayDigital Experience Platform Version7.4 Updateupdate59
LiferayDigital Experience Platform Version7.4 Updateupdate60
LiferayDigital Experience Platform Version7.4 Updateupdate61
LiferayDigital Experience Platform Version7.4 Updateupdate62
LiferayDigital Experience Platform Version7.4 Updateupdate63
LiferayDigital Experience Platform Version7.4 Updateupdate64
LiferayDigital Experience Platform Version7.4 Updateupdate65
LiferayDigital Experience Platform Version7.4 Updateupdate66
LiferayDigital Experience Platform Version7.4 Updateupdate67
LiferayDigital Experience Platform Version7.4 Updateupdate68
LiferayDigital Experience Platform Version7.4 Updateupdate69
LiferayDigital Experience Platform Version7.4 Updateupdate70
LiferayDigital Experience Platform Version7.4 Updateupdate71
LiferayDigital Experience Platform Version7.4 Updateupdate72
LiferayDigital Experience Platform Version7.4 Updateupdate73
LiferayDigital Experience Platform Version7.4 Updateupdate74
LiferayDigital Experience Platform Version7.4 Updateupdate75
LiferayDigital Experience Platform Version7.4 Updateupdate76
LiferayDigital Experience Platform Version7.4 Updateupdate77
LiferayDigital Experience Platform Version7.4 Updateupdate78
LiferayDigital Experience Platform Version7.4 Updateupdate79
LiferayDigital Experience Platform Version7.4 Updateupdate80
LiferayDigital Experience Platform Version7.4 Updateupdate81
LiferayDigital Experience Platform Version7.4 Updateupdate82
LiferayDigital Experience Platform Version7.4 Updateupdate83
LiferayDigital Experience Platform Version7.4 Updateupdate84
LiferayDigital Experience Platform Version7.4 Updateupdate85
LiferayDigital Experience Platform Version7.4 Updateupdate86
LiferayDigital Experience Platform Version7.4 Updateupdate87
LiferayDigital Experience Platform Version7.4 Updateupdate88
LiferayDigital Experience Platform Version7.4 Updateupdate89
LiferayDigital Experience Platform Version7.4 Updateupdate90
LiferayDigital Experience Platform Version7.4 Updateupdate91
LiferayDigital Experience Platform Version7.4 Updateupdate92
LiferayDigital Experience Platform Version2023.q3.0
LiferayDigital Experience Platform Version2023.q3.1
LiferayDigital Experience Platform Version2023.q3.2
LiferayDigital Experience Platform Version2023.q3.3
LiferayDigital Experience Platform Version2023.q3.4
LiferayDigital Experience Platform Version2023.q3.5
LiferayLiferay Portal Version >= 7.4.3.45 < 7.4.3.102
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.547
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.