CVE-2024-25607
- EPSS 0.13%
- Veröffentlicht 20.02.2024 10:15:08
- Zuletzt bearbeitet 11.12.2024 18:01:46
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defa...
CVE-2024-25608
- EPSS 0.47%
- Veröffentlicht 20.02.2024 10:15:08
- Zuletzt bearbeitet 11.12.2024 17:56:22
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPL...
CVE-2024-25609
- EPSS 0.51%
- Veröffentlicht 20.02.2024 10:15:08
- Zuletzt bearbeitet 11.12.2024 17:55:21
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two for...
CVE-2024-25604
- EPSS 0.18%
- Veröffentlicht 20.02.2024 09:15:09
- Zuletzt bearbeitet 10.12.2024 22:59:32
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticate...
CVE-2024-25605
- EPSS 0.24%
- Veröffentlicht 20.02.2024 09:15:09
- Zuletzt bearbeitet 10.12.2024 22:20:47
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content te...
CVE-2024-25606
- EPSS 0.14%
- Veröffentlicht 20.02.2024 09:15:09
- Zuletzt bearbeitet 11.12.2024 14:27:37
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy wi...
CVE-2024-25150
- EPSS 0.24%
- Veröffentlicht 20.02.2024 08:15:07
- Zuletzt bearbeitet 10.12.2024 23:01:58
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated u...
CVE-2024-25149
- EPSS 0.26%
- Veröffentlicht 20.02.2024 07:15:10
- Zuletzt bearbeitet 10.12.2024 23:03:54
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to ...
CVE-2023-44308
- EPSS 0.19%
- Veröffentlicht 20.02.2024 07:15:08
- Zuletzt bearbeitet 28.01.2025 21:34:39
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet...
CVE-2023-5190
- EPSS 0.32%
- Veröffentlicht 20.02.2024 06:15:07
- Zuletzt bearbeitet 28.01.2025 21:34:19
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary exter...