← Back

CVE-2023-35029

nvd nist
Published: Jun 15, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.

Affected (8)

2 products
Dxp
Liferay Portal
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update_70
Version 7.4 update_71
Version 7.4 update_72
Version 7.4 update_73
Version 7.4 update_74
Version 7.4 update_75
Version 7.4 update_76
From 7.4.3.70 to 7.4.3.77

Timeline

No history available yet.