CVE-2023-35029: Medium severity Liferay DXP vulnerability
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the comliferaylayoutadminwebportletGroupPagesPortletbackURL parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35029?
CVE-2023-35029 is an open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76, which allows remote attackers to redirect users to arbitrary external URLs.
How can the open redirect vulnerability be exploited?
The open redirect vulnerability can be exploited by manipulating the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter to redirect users to arbitrary external URLs.
What is the severity of CVE-2023-35029?
CVE-2023-35029 has a severity value of 6.1, which is considered medium.
Which software versions are affected by CVE-2023-35029?
CVE-2023-35029 affects Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76.
How can I fix CVE-2023-35029?
To fix CVE-2023-35029, it is recommended to upgrade to a secure version of Liferay Portal or Liferay DXP.