Skip to main content

CVE-2025-4599: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Liferay Portal

Low
VulnerabilityCVE-2025-4599cvecve-2025-4599cwe-79
Published: Mon Aug 04 2025 (08/04/2025, 21:18:14 UTC)
Source: CVE Database V5
Vendor/Project: Liferay
Product: Portal

Description

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript into the fragment portlet URL.

Technical Details

Data Version
5.1
Assigner Short Name
Liferay
Date Reserved
2025-05-12T17:02:55.131Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 689126f9ad5a09ad00e339fc

Added to database: 8/4/2025, 9:32:41 PM

Last updated: 8/4/2025, 9:32:41 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats