CVE-2024-25602: XSS
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into an organization’s “Name” text field
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25602?
CVE-2024-25602 is classified as a stored cross-site scripting (XSS) vulnerability that can be exploited by authenticated users.
How do I fix CVE-2024-25602?
To fix CVE-2024-25602, upgrade to Liferay Portal 7.4.3.4 or higher, or Liferay DXP 7.3 service pack 3 or higher.
Which versions are affected by CVE-2024-25602?
CVE-2024-25602 affects Liferay Portal versions from 7.2.0 to 7.4.2 and Liferay DXP 7.3 before service pack 3.
Can CVE-2024-25602 be exploited remotely?
Yes, CVE-2024-25602 can be exploited remotely by authenticated users.
What type of vulnerability is CVE-2024-25602?
CVE-2024-25602 is a stored cross-site scripting (XSS) vulnerability allowing injection of malicious scripts.