Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Aug 23, 2025 
          to the GitHub Advisory Database
          •
          Updated Aug 25, 2025 
      
  
Package
Affected versions
< 5.0.69
  Patched versions
5.0.69
  Description
        Published by the National Vulnerability Database
      Aug 23, 2025 
    
  
        Published to the GitHub Advisory Database
      Aug 23, 2025 
    
  
        Reviewed
      Aug 25, 2025 
    
  
        Last updated
      Aug 25, 2025 
    
  
Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
References