Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-25608


HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.


Published

2024-02-20T10:15:08.530

Last Modified

2024-12-11T17:56:22.230

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-601
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application liferay digital_experience_platform < 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay liferay_portal < 7.4.3.19 Yes

References