Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pwh-9q9q-5r9c

Опубликовано: 27 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter

Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter.

Пакеты

Наименование

com.liferay:com.liferay.layout.admin.web

maven
Затронутые версииВерсия исправления

>= 5.0.8, < 5.0.157

5.0.157

EPSS

Процентиль: 14%
0.00046
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter.

EPSS

Процентиль: 14%
0.00046
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-601