In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
History

Tue, 13 May 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Liferay digital Experience Platform
CPEs cpe:2.3:a:liferay:dxp:7.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:*:*:*:*:*:*:*
Vendors & Products Liferay dxp
Liferay digital Experience Platform

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-09-24T14:56:23

Updated: 2024-08-04T13:30:22.352Z

Reserved: 2020-07-20T00:00:00

Link: CVE-2020-15840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-24T15:15:14.080

Modified: 2025-05-13T18:17:51.450

Link: CVE-2020-15840

cve-icon Redhat

No data.