NA

CVE-2023-5190

Published: 20/02/2024 Updated: 20/02/2024

Vulnerability Summary

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 up to and including 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote malicious users to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.