QID 731148
Date Published: 2024-02-12
QID 731148: Liferay Portal Denial of Service (DoS) Vulnerability (CVE-2024-25144)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-25144: The IFrame widget in Liferay Portal does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self-referencing IFrame..
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.26.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
CVEs related to QID 731148
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-25144 |
|