First published: Wed Feb 21 2024(Updated: )
Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.
Credit: security@liferay.com security@liferay.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.liferay.portal:release.dxp.bom | >=7.2.0<7.2.10.fp17 | 7.2.10.fp17 |
maven/com.liferay.portal:release.dxp.bom | >=7.3.0<7.3.10.u4 | 7.3.10.u4 |
maven/com.liferay.portal:release.portal.bom | <=7.4.2 | |
Liferay 7.4 GA | <7.4.3.4 | |
Liferay DXP | <7.2 | |
Liferay DXP | =7.2 | |
Liferay DXP | =7.2-fix_pack_1 | |
Liferay DXP | =7.2-fix_pack_10 | |
Liferay DXP | =7.2-fix_pack_11 | |
Liferay DXP | =7.2-fix_pack_12 | |
Liferay DXP | =7.2-fix_pack_13 | |
Liferay DXP | =7.2-fix_pack_14 | |
Liferay DXP | =7.2-fix_pack_15 | |
Liferay DXP | =7.2-fix_pack_16 | |
Liferay DXP | =7.2-fix_pack_2 | |
Liferay DXP | =7.2-fix_pack_3 | |
Liferay DXP | =7.2-fix_pack_4 | |
Liferay DXP | =7.2-fix_pack_5 | |
Liferay DXP | =7.2-fix_pack_6 | |
Liferay DXP | =7.2-fix_pack_7 | |
Liferay DXP | =7.2-fix_pack_8 | |
Liferay DXP | =7.2-fix_pack_9 | |
Liferay DXP | =7.2-service_pack_1 | |
Liferay DXP | =7.2-service_pack_2 | |
Liferay DXP | =7.2-service_pack_3 | |
Liferay DXP | =7.2-service_pack_4 | |
Liferay DXP | =7.2-service_pack_5 | |
Liferay DXP | =7.3 | |
Liferay DXP | =7.3-fix_pack_1 | |
Liferay DXP | =7.3-fix_pack_2 | |
Liferay DXP | =7.3-service_pack_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25601 is a stored cross-site scripting (XSS) vulnerability that can allow remote authenticated users to execute scripts in the context of other users' sessions.
To fix CVE-2024-25601, upgrade to Liferay Portal versions 7.2.10.fp17, 7.3.10.u4, or later, or apply the relevant patches provided for older versions.
CVE-2024-25601 affects Liferay Portal versions 7.2.0 through 7.4.2, Liferay DXP 7.3 before service pack 3, and older unsupported versions.
No, CVE-2024-25601 can only be exploited by authenticated users with the appropriate permissions in the system.
The potential impacts of CVE-2024-25601 include unauthorized access to cookies or sensitive information and the ability to perform actions on behalf of other users.