Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.1.0, <= 7.4.3.111
A stored cross-site scripting vulnerability has been identified in multiple versions of Liferay Portal and Liferay DXP. This vulnerability allows remote authenticated users to inject arbitrary web scripts or HTML. The injection occurs through a crafted payload placed in a user's first, middle, or last name text field. Affected areas include page comments widgets, blog entry comments, document and media document comments, message board messages, wiki page comments, and other widgets or apps that support mentions.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to Liferay Portal 7.4.3.112, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.6, or Liferay DXP 2023.Q3.9.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.