Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented
Moderate severity
GitHub Reviewed
Published
Sep 23, 2022
to the GitHub Advisory Database
•
Updated Jul 16, 2025
Package
Affected versions
< 7.9.0
Patched versions
7.9.0
>= 7.0.10.fp91, < 7.0.10.fp101
>= 7.1.10.fp17, < 7.1.10.fp25
>= 7.2.10.fp5, < 7.2.10.fp14
7.0.10.fp101
7.1.10.fp25
7.2.10.fp14
Description
Published by the National Vulnerability Database
Sep 22, 2022
Published to the GitHub Advisory Database
Sep 23, 2022
Reviewed
Jul 16, 2025
Last updated
Jul 16, 2025
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect
parameter (2)FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.References