6.1

CVE-2024-25609

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect. This vulnerability is the result of an incomplete fix in CVE-2022-28977.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_12
LiferayDigital Experience Platform Version7.2 Updatefix_pack_13
LiferayDigital Experience Platform Version7.2 Updatefix_pack_14
LiferayDigital Experience Platform Version7.2 Updatefix_pack_15
LiferayDigital Experience Platform Version7.2 Updatefix_pack_16
LiferayDigital Experience Platform Version7.2 Updatefix_pack_17
LiferayDigital Experience Platform Version7.2 Updatefix_pack_18
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Updateservice_pack_1
LiferayDigital Experience Platform Version7.2 Updateservice_pack_2
LiferayDigital Experience Platform Version7.2 Updateservice_pack_3
LiferayDigital Experience Platform Version7.2 Updateservice_pack_4
LiferayDigital Experience Platform Version7.2 Updateservice_pack_5
LiferayDigital Experience Platform Version7.2 Updateservice_pack_6
LiferayDigital Experience Platform Version7.3 Updateservice_pack_3
LiferayDigital Experience Platform Version7.4 Update-
LiferayDigital Experience Platform Version7.4 Updateupdate1
LiferayDigital Experience Platform Version7.4 Updateupdate2
LiferayDigital Experience Platform Version7.4 Updateupdate3
LiferayDigital Experience Platform Version7.4 Updateupdate4
LiferayDigital Experience Platform Version7.4 Updateupdate5
LiferayDigital Experience Platform Version7.4 Updateupdate6
LiferayDigital Experience Platform Version7.4 Updateupdate7
LiferayDigital Experience Platform Version7.4 Updateupdate8
LiferayLiferay Portal Version < 7.4.3.13
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.653
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.