Description
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.
Remediation
References
Related Vulnerabilities
Dolibarr Improper Handling of Case Sensitivity Vulnerability (CVE-2026-89012)
WordPress Plugin Easy FancyBox Unspecified Vulnerability (1.3.4.9)
YOURLS Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2021-3734)
WordPress Plugin Accordion Cross-Site Scripting (2.2.8)
WordPress Plugin Unite Gallery Lite Multiple Vulnerabilities (1.4.6)