-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:release.portal.bom | maven | >= 7.1.0, < 7.4.3.13 | 7.4.3.13 |
The vulnerability description explicitly states XSS occurs via crafted payloads in facet labels. In Liferay's architecture, facet rendering is typically handled by JSP templates. The absence of output encoding in the label rendering context would directly enable this vulnerability. While exact code isn't available, the Modified Facet widget's JSP is the most probable location based on Liferay's component structure and common XSS patterns in Java web applications.
A Semantic Attack on Google Gemini - Read the Latest Research