The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-835 |
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-02-08T03:25:31.037Z
Updated: 2024-10-02T15:31:02.494Z
Reserved: 2024-02-06T10:32:42.566Z
Link: CVE-2024-25144
Vulnrichment
Updated: 2024-08-01T23:36:21.643Z
NVD
Status : Modified
Published: 2024-02-08T04:15:07.763
Modified: 2024-11-21T09:00:20.550
Link: CVE-2024-25144
Redhat
No data.