CVE-2023-5190

Description

Open redirect vulnerability in the Countries Managements edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.323

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-47795,CVE-2023-42496,CVE-2023-40191,CVE-2023-5190 are fixed in Liferay - release.dxp.bom 3.6Windows
Vulnerabilities CVE-2023-5190 are affected in Liferay - release.dxp.bom 7.4.13Windows
Vulnerabilities CVE-2023-5190 are fixed in Liferay - release.portal.bom 7.4.3.102Windows
Vulnerabilities CVE-2023-47795,CVE-2023-42496,CVE-2023-40191,CVE-2023-5190 are fixed in Liferay - release.dxp.bom for Linux 3.6Linux
Vulnerabilities CVE-2023-5190 are affected in Liferay - release.dxp.bom for Linux 7.4.13Linux
Vulnerabilities CVE-2023-5190 are fixed in Liferay - release.portal.bom for Linux 7.4.3.102Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234