CVE-2025-62249: XSS
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.Q3.2, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20, and 2023.Q4.0 through 2023.Q4.10 allows an remote non-authenticated attacker to inject JavaScript into the googlegadget.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62249?
CVE-2025-62249 is rated as a medium severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-62249?
To mitigate CVE-2025-62249, it is recommended to upgrade Liferay Portal to version 7.4.4 or later.
What versions of Liferay are affected by CVE-2025-62249?
CVE-2025-62249 affects Liferay Portal versions 7.4.0 to 7.4.3.132 and Liferay DXP versions Q1.0 through Q3.2.
What kind of vulnerability is CVE-2025-62249?
CVE-2025-62249 is a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can CVE-2025-62249 be exploited remotely?
Yes, CVE-2025-62249 can be exploited remotely without authentication, putting affected systems at risk.