Description
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-7821 | Liferay Portal and Liferay DXP Bypass via Double Encoded URL |
Github GHSA |
GHSA-vrwx-q9pj-x488 | Liferay Portal and Liferay DXP Bypass via Double Encoded URL |
References
History
Tue, 13 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay digital Experience Platform
|
|
| CPEs | cpe:2.3:a:liferay:dxp:7.1:*:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:*:*:*:*:*:*:* |
cpe:2.3:a:liferay:digital_experience_platform:7.0:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:*:*:*:*:*:*:* |
| Vendors & Products |
Liferay dxp
|
Liferay digital Experience Platform
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:30:22.352Z
Reserved: 2020-07-20T00:00:00.000Z
Link: CVE-2020-15840
No data.
Status : Modified
Published: 2020-09-24T15:15:14.080
Modified: 2025-05-13T18:17:51.450
Link: CVE-2020-15840
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA