Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfxj-gvqg-mj44

Опубликовано: 07 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.8

Описание

Liferay Profile Widget does not prevent vCard extension spoofing

The Profile Widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0-ga1, < 7.4.3.112-ga112

7.4.3.112-ga112

EPSS

Процентиль: 22%
0.00072
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
4 месяца назад

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

EPSS

Процентиль: 22%
0.00072
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79