QID 731186

Date Published: 2024-02-22

QID 731186: Liferay Portal Open Redirect Vulnerability (CVE-2024-25609)

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

CVE-2024-25609: HtmlUtil.escapeRedirect in Liferay Portal and Liferay DXP can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.12.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.

Successful exploitation of this vulnerability allows remote attackers to redirect users to arbitrary external URLs.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731186

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25609