Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 up to and including 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote malicious users to redirect users to arbitrary external URLs via the 'redirect' parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
liferay dxp 7.0 |
||
liferay dxp 7.1 |
||
liferay dxp 7.2 |
||
liferay liferay portal |