PT-2024-21037 · Liferay · Liferay Portal+1

Published

2024-02-20

·

Updated

2025-12-24

·

CVE-2024-25608

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.2.0 through 7.4.3.18 Liferay DXP 7.4 before update 19 Liferay DXP 7.3 before update 4 Liferay DXP 7.2 before fix pack 19
Description The issue allows remote attackers to redirect users to arbitrary external URLs via parameters such as redirect, FORWARD URL, noSuchEntryRedirect, and others that rely on HtmlUtil.escapeRedirect. This can be achieved by circumventing HtmlUtil.escapeRedirect using the 'REPLACEMENT CHARACTER' (U+FFFD). Threat actors are leveraging this issue for phishing, including credential phishing on U.S. government sites.
Recommendations For Liferay Portal versions 7.2.0 through 7.4.3.18, update to a version after 7.4.3.18 or apply the necessary fix. For Liferay DXP 7.4 before update 19, apply update 19. For Liferay DXP 7.3 before update 4, apply update 4. For Liferay DXP 7.2 before fix pack 19, apply fix pack 19. As a temporary workaround, consider restricting access to parameters such as redirect, FORWARD URL, and noSuchEntryRedirect to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25608
GHSA-548X-J6X6-HCV4

Affected Products

Liferay Dxp
Liferay Portal