Логотип exploitDog
bind:CVE-2025-62266
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62266

Количество 2

Количество 2

nvd логотип

CVE-2025-62266

3 месяца назад

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs. This vulnerability can be mitigated by changing the redirect URL security from IP to domain.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-f5vh-4rj2-w8r8

3 месяца назад

Liferay Portal is vulnerable to DNS rebinding attacks

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62266

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs. This vulnerability can be mitigated by changing the redirect URL security from IP to domain.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-f5vh-4rj2-w8r8

Liferay Portal is vulnerable to DNS rebinding attacks

0%
Низкий
3 месяца назад

Уязвимостей на страницу