Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-20T06:29:07.856Z

Updated: 2024-08-28T16:29:31.044Z

Reserved: 2023-09-28T11:23:54.828Z

Link: CVE-2023-44308

cve-icon Vulnrichment

Updated: 2024-08-02T19:59:52.152Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T07:15:08.033

Modified: 2024-02-20T19:50:53.960

Link: CVE-2023-44308

cve-icon Redhat

No data.