CVE Vulnerabilities

CVE-2020-15840

Published: Sep 24, 2020 | Modified: May 13, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property portlet.resource.id.banned.paths.regexp can be bypassed with doubled encoded URLs.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay7.0 (including)7.0 (including)
Digital_experience_platformLiferay7.1 (including)7.1 (including)
Digital_experience_platformLiferay7.2 (including)7.2 (including)
Liferay_portalLiferay*7.3.1 (excluding)
Liferay_portalLiferay6.2 (including)6.2 (including)

References