Описание
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 update 32 through update 92 allows an remote authenticated user to inject JavaScript into the embedded message field from the form container.
Уязвимые конфигурации
Конфигурация 1Версия от 2024.Q1.1 (включая) до 2024.Q1.17 (исключая)Версия от 2024.Q2.1 (включая) до 2024.Q2.13 (включая)Версия от 2024.q3.1 (включая) до 2024.q3.13 (включая)Версия от 2024.q4.0 (включая) до 2024.q4.7 (включая)Версия от 2025.Q1.0 (включая) до 2025.Q1.8 (исключая)Версия от 7.4.3.32 (включая) до 7.4.3.132 (включая)
Одно из
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.0003
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
github
6 месяцев назад
Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form Container
EPSS
Процентиль: 8%
0.0003
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79