Details
-
Bug
-
Status: Verified
-
Resolution: Unresolved
-
7.3.6 CE GA7
-
None
-
None
-
4
Description
From Personal Menu (clicking on avatar) you can navigate to specific portlet displayed on a virtual /manage/ page by specifying the portlet ID. There are some pre-defined entries for Notifications or pending Workflow items, but this URL can be crafted
However, there is no input validation for this ID so when a non-existing ID is used, the NPE is thrown (recorded in the log).
You can try here https://liferay.dev/manage?p_p_id=nonsense