Description
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
Remediation
References
Related Vulnerabilities
Werkzeug WSGI Improper Handling of Windows Device Names Vulnerability (CVE-2026-27199)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7873)
WordPress Plugin More Fields Cross-Site Request Forgery (2.1)
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-43810)