CVE-2025-62238
published 2025-10-10CVE-2025-62238: Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.21%
10.6th percentile
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected into a Account's “Name“ text field.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | >= 2023.q3.1 < 2023.q3.9 | 2023.q3.9 |
| liferay | digital_experience_platform | >= 2023.q4.0 < 2023.q4.6 | 2023.q4.6 |
| liferay | dxp | 2023.Q3.1 – 2023.Q3.8 | — |
| liferay | dxp | 2023.Q4.0 – 2023.Q4.5 | — |
| liferay | dxp | 7.4.13-u21 – 7.4.13-u92 | — |
| liferay | liferay_portal | >= 7.4.3.21 < 7.4.3.112 | 7.4.3.112 |
| liferay | portal | 7.4.3.21 – 7.4.3.111 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.04.8MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
osv·2025-10-10
CVE-2025-62238 [MEDIUM] Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected into a Account's “Name“ text field.
GHSA
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
ghsa·2025-10-10
CVE-2025-62238 [MEDIUM] CWE-79 Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected into a Account's “Name“ text field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-10
Published