Description
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject JavaScript through the organization site names. The malicious payload is stored and executed without proper sanitization or escaping.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2023-21742 Vulnerability (CVE-2023-21742)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.14)
WordPress Plugin JS Help Desk (formerly JS Support Ticket) SQL Injection (2.1.0)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2359)
WordPress Plugin BulletProof Security Cross-Site Scripting (.52.4)