CVE-2024-25610: XSS
In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a crafted payload injected into a blog entry’s content text field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:com.liferay.portal.webto a version that resolves this vulnerability.Fixed in 5.0.96 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp19 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u9 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.13
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25610?
CVE-2024-25610 has a high severity level due to potential cross-site scripting vulnerabilities in Liferay Portal.
How do I fix CVE-2024-25610?
To fix CVE-2024-25610, upgrade to the latest recommended versions of Liferay Portal or Liferay DXP listed in the vulnerability report.
Which versions of Liferay are affected by CVE-2024-25610?
CVE-2024-25610 affects Liferay Portal versions 7.2.0 through 7.4.3.12 and older unsupported versions, as well as specific versions of Liferay DXP.
Can remote authenticated users exploit CVE-2024-25610?
Yes, CVE-2024-25610 allows remote authenticated users to inject JavaScript into blog entries due to insufficient sanitization.
Are older versions of Liferay affected by CVE-2024-25610?
Yes, older unsupported versions of Liferay Portal and Liferay DXP prior to the specified fixed versions are also affected by CVE-2024-25610.