Required CVE Record Information
Description
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
6.1 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Product Status
Learn moreVersions 1 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: unaffected
affected
Credits
- Henrik Bayer (NDIx) reporter
References 1 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-35029 vendor-advisoryx_transferred