Open redirect in Liferay Enterprise Portal - #VU13836

 

Open redirect in Liferay Enterprise Portal - #VU13836

Published: July 12, 2018


Vulnerability identifier: #VU13836
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to redirect the target user to external websites.

The weakness exists due to open redirect. A remote attacker can use a specially crafted image link, trick the victim into opening it and redirect users to malicious website.

Affected software

Liferay Enterprise Portal

Remediation

Update to version 7.1 or later.

Liferay Enterprise Portal - update to 7.1

External References

Related Security Bulletins