Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-20T06:03:45.941Z

Updated: 2024-08-02T07:52:07.791Z

Reserved: 2023-09-26T05:30:24.925Z

Link: CVE-2023-5190

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:07.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T06:15:07.680

Modified: 2024-02-20T19:50:53.960

Link: CVE-2023-5190

cve-icon Redhat

No data.