QID 731115
Date Published: 2024-01-30
QID 731115: Liferay Portal Multiple Parameter Redirection Vulnerability (CVE-2022-28977)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
The HtmlUtil.escapeRedirect function in Liferay Portal can be circumvented by using multiple forward slashes, allowing remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter, 'FORWARD_URL' parameter, and other parameters that rely on HtmlUtil.escapeRedirect.
Affected Versions:
Liferay Portal 7.3.1 - 7.3.7
Liferay Portal 7.4.0 - 7.4.2
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploitation of this vulnerability allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.
CVEs related to QID 731115
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-28977 |
|