Loading HuntDB...

GHSA-22w7-m5f8-87vh

GitHub Security Advisory

Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.

Affected Packages

Maven com.liferay.portal:release.portal.bom
Affected versions: 7.4.3.70-ga70 (fixed in 7.4.3.77-ga77)
Maven com.liferay.portal:release.dxp.bom
Affected versions: 7.4.13.u70 (last affected: 7.4.13.u76)

Related CVEs

Key Information

GHSA ID
GHSA-22w7-m5f8-87vh
Published
June 15, 2023 6:30 AM
Last Modified
August 8, 2025 9:12 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.liferay.portal:release.portal.bom
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.