CVE-2024-25608

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
LiferayCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
liferaydigital_experience_platform
𝑥
< 7.2
liferaydigital_experience_platform
7.2
liferaydigital_experience_platform
7.2:fix_pack_1
liferaydigital_experience_platform
7.2:fix_pack_10
liferaydigital_experience_platform
7.2:fix_pack_11
liferaydigital_experience_platform
7.2:fix_pack_12
liferaydigital_experience_platform
7.2:fix_pack_13
liferaydigital_experience_platform
7.2:fix_pack_14
liferaydigital_experience_platform
7.2:fix_pack_15
liferaydigital_experience_platform
7.2:fix_pack_16
liferaydigital_experience_platform
7.2:fix_pack_17
liferaydigital_experience_platform
7.2:fix_pack_18
liferaydigital_experience_platform
7.2:fix_pack_2
liferaydigital_experience_platform
7.2:fix_pack_3
liferaydigital_experience_platform
7.2:fix_pack_4
liferaydigital_experience_platform
7.2:fix_pack_5
liferaydigital_experience_platform
7.2:fix_pack_6
liferaydigital_experience_platform
7.2:fix_pack_7
liferaydigital_experience_platform
7.2:fix_pack_8
liferaydigital_experience_platform
7.2:fix_pack_9
liferaydigital_experience_platform
7.2:service_pack_1
liferaydigital_experience_platform
7.2:service_pack_2
liferaydigital_experience_platform
7.2:service_pack_3
liferaydigital_experience_platform
7.2:service_pack_4
liferaydigital_experience_platform
7.2:service_pack_5
liferaydigital_experience_platform
7.2:service_pack_6
liferaydigital_experience_platform
7.3
liferaydigital_experience_platform
7.3:fix_pack_1
liferaydigital_experience_platform
7.3:fix_pack_2
liferaydigital_experience_platform
7.3:service_pack_1
liferaydigital_experience_platform
7.3:service_pack_3
liferaydigital_experience_platform
7.4
liferaydigital_experience_platform
7.4:update1
liferaydigital_experience_platform
7.4:update10
liferaydigital_experience_platform
7.4:update11
liferaydigital_experience_platform
7.4:update12
liferaydigital_experience_platform
7.4:update13
liferaydigital_experience_platform
7.4:update14
liferaydigital_experience_platform
7.4:update15
liferaydigital_experience_platform
7.4:update16
liferaydigital_experience_platform
7.4:update17
liferaydigital_experience_platform
7.4:update18
liferaydigital_experience_platform
7.4:update2
liferaydigital_experience_platform
7.4:update3
liferaydigital_experience_platform
7.4:update4
liferaydigital_experience_platform
7.4:update5
liferaydigital_experience_platform
7.4:update6
liferaydigital_experience_platform
7.4:update7
liferaydigital_experience_platform
7.4:update8
liferaydigital_experience_platform
7.4:update9
liferayliferay_portal
𝑥
< 7.4.3.19
𝑥
= Vulnerable software versions