Количество 2
Количество 2
CVE-2024-25147
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
GHSA-xpjg-7hx7-wgcx
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-25147 Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links. | CVSS3: 9.6 | 0% Низкий | почти 2 года назад | |
GHSA-xpjg-7hx7-wgcx Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting | CVSS3: 9.6 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу