Record summary

CVE-2024-25608 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 29, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2024 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus

Default status: unknown

CVE List7.4.13 to ≤ 7.4.13.u18affected
7.3.10 to ≤ 7.3.10-dxp-3affected
7.2.10 to ≤ 7.2.10-dxp-18affected

Default status: unknown

CVE List7.2.0 to ≤ 7.4.3.18affected
VulnCheckVersion data not supplied

com.liferay.portal:release.dxp.bom

Browse Maven / com.liferay.portal:release.dxp.bom
GitHub AdvisoryBefore 7.2.10.fp19 · Fixed in 7.2.10.fp19affected
7.3.0 to < 7.3.10.u4 · Fixed in 7.3.10.u4affected
7.4.0 to < 7.4.13.u19 · Fixed in 7.4.13.u19affected

com.liferay.portal:release.portal.bom

Browse Maven / com.liferay.portal:release.portal.bom
GitHub Advisory7.2.0 to < 7.4.3.19-ga19 · Fixed in 7.4.3.19-ga19affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLiferay Portal - Open RedirectCVSS 6.1

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.

Impact

Attackers can redirect users to arbitrary external URLs, potentially leading to phishing or malware distribution.

Remediation

Update to the latest supported versions of Liferay Portal and DXP, applying all security patches.

WeaknessesCWE-601
Authorsdaffainfo
Template tagscvecve2024liferayliferay-portaldigital-experience-platformopen-redirectvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*,cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:129457226
FOFA: icon_hash=129457226

Source: ProjectDiscovery

References

5