CVE-2025-4599: XSS
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript into the fragment portlet URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4599?
CVE-2025-4599 has been categorized as a high severity vulnerability due to its potential for exploitation via postMessage-based attacks.
How do I fix CVE-2025-4599?
To mitigate CVE-2025-4599, update Liferay Portal to version 7.4.3.133 or later and Liferay DXP to versions beyond those listed as vulnerable.
What versions are affected by CVE-2025-4599?
CVE-2025-4599 affects Liferay Portal versions 7.4.3.61 through 7.4.3.132 and Liferay DXP versions 2024.Q4.1 through 2024.Q4.5, among others.
What types of attacks can exploit CVE-2025-4599?
CVE-2025-4599 can be exploited through cross-origin attacks leveraging the postMessage API.
Is there a patch available for CVE-2025-4599?
Yes, patches for CVE-2025-4599 are available in the updated versions of both Liferay Portal and Liferay DXP.