CVE-2025-62263: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page.
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Organization’s “Name” text field to (1) view account page, (2) view account organization page, or (3) select account organization page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62263?
CVE-2025-62263 has been rated with a significant severity level due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2025-62263?
To fix CVE-2025-62263, update your Liferay Portal or Liferay DXP installations to the latest patched versions provided by Liferay.
What versions are affected by CVE-2025-62263?
CVE-2025-62263 affects Liferay Portal versions 7.3.7 through 7.4.3.103 and Liferay DXP versions 2023.Q3.1 through 2023.Q3.4.
Can CVE-2025-62263 lead to data theft?
Yes, if exploited, CVE-2025-62263 can allow attackers to execute arbitrary scripts, potentially leading to data theft.
Is CVE-2025-62263 exploitable without authentication?
CVE-2025-62263 can be exploited without authentication, making it critical to address if your systems are running affected versions.