Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88g3-pv3w-5wmr

Опубликовано: 09 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.6

Описание

Liferay Portal is vulnerable to XSS attacks via its remote app title field

A stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.

Пакеты

Наименование

com.liferay:com.liferay.client.extension.web

maven
Затронутые версииВерсия исправления

>= 1.0.71, < 2.0.27

2.0.27

EPSS

Процентиль: 6%
0.00023
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
5 месяцев назад

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.

EPSS

Процентиль: 6%
0.00023
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-79