Open redirect in Liferay Enterprise Portal - #VU13836
Published: July 12, 2018
Vulnerability identifier: #VU13836
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to redirect the target user to external websites.
The weakness exists due to open redirect. A remote attacker can use a specially crafted image link, trick the victim into opening it and redirect users to malicious website.
The weakness exists due to open redirect. A remote attacker can use a specially crafted image link, trick the victim into opening it and redirect users to malicious website.
Affected software
Liferay Enterprise Portal
Remediation
Update to version 7.1 or later.
Liferay Enterprise Portal - update to 7.1