HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect. This vulnerability is the result of an incomplete fix in CVE-2022-28977.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-02-20T09:37:55.362Z
Updated: 2024-08-23T19:19:20.308Z
Reserved: 2024-02-08T13:57:11.426Z
Link: CVE-2024-25609
Vulnrichment
Updated: 2024-08-01T23:44:09.679Z
NVD
Status : Awaiting Analysis
Published: 2024-02-20T10:15:08.707
Modified: 2024-02-20T19:50:53.960
Link: CVE-2024-25609
Redhat
No data.