CVE-2024-25608 is an open redirect vulnerability affecting Liferay Portal and DXP versions, allowing remote attackers to redirect users to arbitrary external URLs. This medium-severity vulnerability (CVSS 6.1) has a low attack complexity and requires user interaction, potentially leading to information disclosure and integrity impacts. While not currently in CISA's KEV catalog, it has a high FAUCET Risk Score of 95/100 and an EPSS score indicating a higher-than-average likelihood of exploitation. Although no Metasploit or ExploitDB modules exist, Nuclei templates are available, and there's evidence of community discussion and media coverage, including reports of threat actors exploiting government websites for phishing using similar vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.2:-:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_1:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_10:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.