The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-835 |

Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2024-10-02T15:31:02.494Z
Reserved: 2024-02-06T10:32:42.566Z
Link: CVE-2024-25144

Updated: 2024-08-01T23:36:21.643Z

Status : Modified
Published: 2024-02-08T04:15:07.763
Modified: 2024-11-21T09:00:20.550
Link: CVE-2024-25144

No data.