9.6

CVE-2024-25145 Stored XSS with search results if highlighting is disabled

Description

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.

Severity

9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Version(s)

  • Liferay Portal 7.4.0 through 7.4.3.11
  • Liferay Portal 7.3.0 through 7.3.7
  • Liferay Portal 7.2.0 and 7.2.1
  • Liferay Portal, older unsupported versions
  • Liferay DXP 7.4 before update 8
  • Liferay DXP 7.3 before update 4
  • Liferay DXP 7.2 before fix pack 17
  • Liferay DXP, older unsupported versions

Fixed Version(s)

Publication Date: 

février 6, 2024

Found a Bug?

If you have found, or think you have found a bug, help us to help you by letting us know!

Found a Security Vulnerability?

There's a different process available if you have a security issue to report...

Hall of Fame!

Raise your profile - report security vulnerabilities and enter the Hall of Fame!