CVE-2025-4604: XSS
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4604?
CVE-2025-4604 is considered a critical vulnerability due to its ability to bypass Captcha checks.
How do I fix CVE-2025-4604?
To fix CVE-2025-4604, update Liferay Portal to version 7.4.3.132 or higher, or Liferay DXP to versions beyond the vulnerable ranges specified.
Which versions are affected by CVE-2025-4604?
CVE-2025-4604 affects Liferay Portal versions 7.4.3.80 to 7.4.3.132 and multiple versions of Liferay DXP from 2024.Q1.1 through 2025.Q1.15.
What systems are impacted by CVE-2025-4604?
CVE-2025-4604 impacts Liferay Portal and Liferay DXP installations within the specified version ranges.
Is there a patch for CVE-2025-4604?
Yes, patches are available as updates for the affected Liferay Portal and Liferay DXP versions to address CVE-2025-4604.