CVE-2024-25145: XSS
Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.3.13u8 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.12
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25145?
The severity of CVE-2024-25145 is high due to its potential to allow remote attackers to execute malicious scripts via stored cross-site scripting (XSS).
How do I fix CVE-2024-25145?
To fix CVE-2024-25145, upgrade to Liferay Portal versions 7.2.10.fp17, 7.3.10.u4, or 7.4.3.13u8 and later releases as specified in the remediation guidance.
Which versions of Liferay are affected by CVE-2024-25145?
CVE-2024-25145 affects Liferay Portal versions 7.2.0 through 7.4.3.11 and older unsupported versions, as well as specific Liferay DXP versions.
What type of vulnerability is CVE-2024-25145?
CVE-2024-25145 is categorized as a stored cross-site scripting (XSS) vulnerability in the Liferay Portal's Search Result app.
Can I check if my version of Liferay is vulnerable to CVE-2024-25145?
You can determine your Liferay version against the affected versions listed for CVE-2024-25145 to assess vulnerability.