QID 731186
Date Published: 2024-02-22
QID 731186: Liferay Portal Open Redirect Vulnerability (CVE-2024-25609)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-25609: HtmlUtil.escapeRedirect in Liferay Portal and Liferay DXP can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.12.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote attackers to redirect users to arbitrary external URLs.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731186
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal |
|