Liferay Portal and Liferay DXP Open Redirect Vulnerability in Page Administration

Vulnerability

An open redirect vulnerability has been identified in the page administration feature of Liferay Portal and Liferay DXP. This vulnerability allows remote attackers to redirect users to arbitrary external URLs by exploiting the '_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect' parameter. Affected versions include Liferay Portal 7.4.0 through 7.4.3.97, Liferay Portal 7.3.0 through 7.3.7, Liferay DXP 2023.Q4.0, Liferay DXP 2023.Q3.1 through 2023.Q3.4, Liferay DXP 7.4, Liferay DXP 7.3 GA through U35, and older unsupported versions.

Impact

Exploitation of this vulnerability could lead to open redirect attacks, where users are sent to malicious external sites, potentially causing phishing or other security issues.

Remediation

Users can upgrade to Liferay Portal 7.4.3.98, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.1, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 U36.

Added: Oct 27, 2025, 7:17 PM
Updated: Oct 27, 2025, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.8
exploitability
6.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.