Логотип exploitDog
bind:CVE-2025-43740
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43740

Количество 2

Количество 2

nvd логотип

CVE-2025-43740

6 месяцев назад

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows an remote authenticated attacker to inject JavaScript through the message boards feature available via the web interface.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22jp-w3cg-gvmm

6 месяцев назад

Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43740

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows an remote authenticated attacker to inject JavaScript through the message boards feature available via the web interface.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-22jp-w3cg-gvmm

Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature

0%
Низкий
6 месяцев назад

Уязвимостей на страницу