CVE-2024-25152: XSS
Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25152?
CVE-2024-25152 has been classified as a stored cross-site scripting (XSS) vulnerability, which can lead to potential data theft or session hijacking.
How do I fix CVE-2024-25152?
To mitigate CVE-2024-25152, upgrade to Liferay Portal versions 7.2.10.fp17, 7.3.10.u4, or higher.
Which versions of Liferay are affected by CVE-2024-25152?
CVE-2024-25152 affects Liferay Portal versions 7.2.0 through 7.4.2, as well as Liferay DXP 7.3 prior to service pack 3.
Who can exploit CVE-2024-25152?
Remote authenticated users can exploit CVE-2024-25152 to inject arbitrary web scripts in affected Liferay installations.
Is CVE-2024-25152 present in unsupported Liferay versions?
Yes, CVE-2024-25152 also impacts older unsupported versions of Liferay Portal and Liferay DXP.