Логотип exploitDog
bind:CVE-2024-25610
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-25610

Количество 2

Количество 2

nvd логотип

CVE-2024-25610

почти 2 года назад

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a crafted payload injected into a blog entry’s content text field.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-vvpf-53qx-cxhh

почти 2 года назад

Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-25610

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a crafted payload injected into a blog entry’s content text field.

CVSS3: 9
0%
Низкий
почти 2 года назад
github логотип
GHSA-vvpf-53qx-cxhh

Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)

CVSS3: 9
0%
Низкий
почти 2 года назад

Уязвимостей на страницу