CVE-2024-25147: XSS
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp15 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.4.1 - Upgrade
Upgrade
Liferay DXP 7.3to a version that resolves this vulnerability.Patch service pack 3 - Upgrade
Upgrade
Liferay Portal 7.2to a version that resolves this vulnerability.Patch fix pack 15
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25147?
CVE-2024-25147 is classified as a medium severity Cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
How do I fix CVE-2024-25147?
To mitigate CVE-2024-25147, upgrade to Liferay Portal version 7.2.10.fp15 or 7.3.10.u4, or to any version of Liferay Portal after 7.4.1.
Which Liferay versions are affected by CVE-2024-25147?
CVE-2024-25147 affects Liferay Portal versions 7.2.0 through 7.4.1, and older unsupported versions, as well as Liferay DXP 7.3 before service pack 3.
Can CVE-2024-25147 be exploited by any remote attacker?
Yes, CVE-2024-25147 can be exploited by remote attackers who can craft and inject arbitrary web scripts or HTML.
Is there any workaround for CVE-2024-25147 before applying the fix?
There are no known effective workarounds for CVE-2024-25147 other than upgrading to a patched version.