Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1503

Phishers can redirect users to an untrusted site

Details

    Description

      By altering the redirect parameters in an URL, a phisher can send an unsuspecting user to a malicious site when they hit certain return links or cancel buttons. Such actions should redirect only to the same IP or authorized IP addresses defined in portal(-ext).properties.

      Attachments

        Issue Links

          Activity

            People

              michael.saechang Michael Saechang
              douglas.wong Douglas Wong
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP3 (5.2.7)