Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4g9-5mg6-gfr3

Опубликовано: 10 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.8

Описание

Liferay Portal Commerce is vulnerable to XSS through account "name" field

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

Пакеты

Наименование

com.liferay.commerce:com.liferay.commerce.order.web

maven
Затронутые версииВерсия исправления

>= 5.0.29, < 5.0.101

5.0.101

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
4 месяца назад

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79