CVE-2024-25144

The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L
LiferayCNA
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
liferaydigital_experience_platform
7.2
liferaydigital_experience_platform
7.2:fix_pack_1
liferaydigital_experience_platform
7.2:fix_pack_10
liferaydigital_experience_platform
7.2:fix_pack_11
liferaydigital_experience_platform
7.2:fix_pack_12
liferaydigital_experience_platform
7.2:fix_pack_13
liferaydigital_experience_platform
7.2:fix_pack_14
liferaydigital_experience_platform
7.2:fix_pack_15
liferaydigital_experience_platform
7.2:fix_pack_16
liferaydigital_experience_platform
7.2:fix_pack_17
liferaydigital_experience_platform
7.2:fix_pack_18
liferaydigital_experience_platform
7.2:fix_pack_2
liferaydigital_experience_platform
7.2:fix_pack_3
liferaydigital_experience_platform
7.2:fix_pack_4
liferaydigital_experience_platform
7.2:fix_pack_5
liferaydigital_experience_platform
7.2:fix_pack_6
liferaydigital_experience_platform
7.2:fix_pack_7
liferaydigital_experience_platform
7.2:fix_pack_8
liferaydigital_experience_platform
7.2:fix_pack_9
liferaydxp
7.3
liferaydxp
7.3:sp1
liferaydxp
7.3:sp2
liferaydxp
7.3:sp3
liferaydxp
7.3:update_1
liferaydxp
7.3:update_2
liferaydxp
7.3:update_3
liferaydxp
7.3:update_4
liferaydxp
7.3:update_5
liferaydxp
7.4
liferaydxp
7.4:update_1
liferaydxp
7.4:update_10
liferaydxp
7.4:update_11
liferaydxp
7.4:update_12
liferaydxp
7.4:update_13
liferaydxp
7.4:update_14
liferaydxp
7.4:update_15
liferaydxp
7.4:update_16
liferaydxp
7.4:update_17
liferaydxp
7.4:update_18
liferaydxp
7.4:update_19
liferaydxp
7.4:update_2
liferaydxp
7.4:update_20
liferaydxp
7.4:update_21
liferaydxp
7.4:update_22
liferaydxp
7.4:update_23
liferaydxp
7.4:update_24
liferaydxp
7.4:update_25
liferaydxp
7.4:update_26
liferaydxp
7.4:update_3
liferaydxp
7.4:update_4
liferaydxp
7.4:update_5
liferaydxp
7.4:update_6
liferaydxp
7.4:update_7
liferaydxp
7.4:update_8
liferaydxp
7.4:update_9
liferayliferay_portal
7.2.0 ≤
𝑥
< 7.4.3.26
𝑥
= Vulnerable software versions