In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Liferay digital Experience Platform
|
|
CPEs | cpe:2.3:a:liferay:dxp:7.1:*:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:*:*:*:*:*:*:* |
cpe:2.3:a:liferay:digital_experience_platform:7.0:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:*:*:*:*:*:*:* |
Vendors & Products |
Liferay dxp
|
Liferay digital Experience Platform
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:30:22.352Z
Reserved: 2020-07-20T00:00:00
Link: CVE-2020-15840

No data.

Status : Modified
Published: 2020-09-24T15:15:14.080
Modified: 2025-05-13T18:17:51.450
Link: CVE-2020-15840

No data.