CVE-2020-15840Improper Access Control in Portal

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 58.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 24

Description

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP Bypass via Double Encoded URL2022-05-24
GHSA
Liferay Portal and Liferay DXP Bypass via Double Encoded URL2022-05-24
CVEList
CVE-2020-15840: In Liferay Portal before 72020-09-24
CVE-2020-15840 — Improper Access Control in Portal | cvebase