CVE-2024-25147Cross-site Scripting in Digital Experience Platform

Severity
6.1MEDIUMNVD
CNA9.6
EPSS
0.2%
top 58.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateApr 15

Description

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5liferay/portal7.2.07.4.1
CVEListV5liferay/dxp7.3.107.3.10-dxp-2+1

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting2024-02-21
GHSA
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting2024-02-21
CVEList
CVE-2024-25147: Cross-site scripting (XSS) vulnerability in HtmlUtil2024-02-21

📋Vendor Advisories

2
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime Utility) — CVE-2022-251472024-04-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Application (Apache Portable Runtime Utility) — CVE-2022-251472024-01-15
CVE-2024-25147 — Cross-site Scripting | cvebase