CVE-2024-25144
MEDIUMDescription
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
Is your site exposed to CVE-2024-25144?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | dxp |
| liferay | liferay_portal |
References
Frequently Asked Questions
What is CVE-2024-25144? +
How severe is CVE-2024-25144? +
What products are affected by CVE-2024-25144? +
How do I check if I'm vulnerable to CVE-2024-25144? +
Related Vulnerabilities
OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server …
Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28.0`, and `0.29.0` …
ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead …
There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" …
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker …
Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before …