The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
2024-02-08T04:15:07.763
2025-05-13T18:17:51.450
Modified
CVSSv3.1: 4.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | liferay_portal | < 7.4.3.26 | Yes |