QID 731182

Date Published: 2024-02-22

QID 731182: Liferay Portal Open Redirect Vulnerability (CVE-2024-25608)

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

CVE-2024-25608: HtmlUtil.escapeRedirect in Liferay Portal which allows remote attackers to redirect users to arbitrary external URLs.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.18.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.

Successful exploitation of this vulnerability allows remote attackers to redirect users to arbitrary external URLs.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731182

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25608