CVE-2023-44308

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
Configurations

No configuration.

History

20 Feb 2024, 19:50

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de redireccionamiento abierto en la página de administración de medios adaptables en Liferay DXP 2023.Q3 antes del parche 6 y 7.4 GA hasta la actualización 92 permite a atacantes remotos redirigir a los usuarios a URL externas arbitrarias a través del parámetro _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect.

20 Feb 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 07:15

Updated : 2024-02-20 19:50


NVD link : CVE-2023-44308

Mitre link : CVE-2023-44308

CVE.ORG link : CVE-2023-44308


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')