-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unsanitized user input in first/middle/last name fields being stored and later rendered in Announcements/Alerts widgets. The entry creation services (AnnouncementsEntryServiceImpl, AlertsEntryServiceImpl) are directly responsible for handling user-generated content, while UserLocalService manages the storage of the vulnerable fields. The lack of output encoding/input validation in these components allows XSS payloads to execute when entries are displayed.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:release.portal.bom | maven | <= 7.4.3.13 | 7.4.3.14 |
| com.liferay.portal:release.dxp.bom | maven | >= 7.4.13.u1, < 7.4.13.u10 | 7.4.13.u10 |
| com.liferay.portal:release.dxp.bom | maven | >= 7.3.10.ep3, < 7.3.10.u4 | 7.3.10.u4 |
| com.liferay.portal:release.dxp.bom | maven | >= 7.2.0, < 7.2.10.fp17 | 7.2.10.fp17 |
KEV Misses 88% of Exploited CVEs- Get the report