CVE-2024-25601: XSS
Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
Liferay Portal 7.2.0to a version that resolves this vulnerability.Fixed in 7.4.2 - Upgrade
Upgrade
Liferay DXP 7.3to a version that resolves this vulnerability.Patch service pack 3 - Upgrade
Upgrade
Liferay Portal 7.2to a version that resolves this vulnerability.Patch fix pack 17
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25601?
CVE-2024-25601 is a stored cross-site scripting (XSS) vulnerability that can allow remote authenticated users to execute scripts in the context of other users' sessions.
How do I fix CVE-2024-25601?
To fix CVE-2024-25601, upgrade to Liferay Portal versions 7.2.10.fp17, 7.3.10.u4, or later, or apply the relevant patches provided for older versions.
What versions of Liferay are affected by CVE-2024-25601?
CVE-2024-25601 affects Liferay Portal versions 7.2.0 through 7.4.2, Liferay DXP 7.3 before service pack 3, and older unsupported versions.
Can unauthenticated users exploit CVE-2024-25601?
No, CVE-2024-25601 can only be exploited by authenticated users with the appropriate permissions in the system.
What are the potential impacts of CVE-2024-25601?
The potential impacts of CVE-2024-25601 include unauthorized access to cookies or sensitive information and the ability to perform actions on behalf of other users.