-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in form configuration rendering where user-supplied 'name' field content is stored then displayed without adequate sanitization. Liferay's architecture typically uses JSPs for admin interfaces, and the stored XSS pattern suggests missing output encoding in the configuration view template. While exact code isn't available, the attack vector (form name in configuration) and Liferay's technical stack strongly indicate vulnerable JSP-based rendering logic for form widget settings.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:release.portal.bom | maven | >= 7.1.0, < 7.3.1 | 7.3.1 |
Ongoing coverage of React2Shell