HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-02-20T09:26:10.743Z
Updated: 2024-08-01T23:44:09.704Z
Reserved: 2024-02-08T13:57:11.426Z
Link: CVE-2024-25608
Vulnrichment
Updated: 2024-08-01T23:44:09.704Z
NVD
Status : Awaiting Analysis
Published: 2024-02-20T10:15:08.530
Modified: 2024-02-20T19:50:53.960
Link: CVE-2024-25608
Redhat
No data.