Liferay Portal 7.4.3.8 < 7.4.3.112 XSS

medium Nessus Plugin ID 272737

Synopsis

The remote host is missing a security update.

Description

Reflected cross-site scripting (XSS) vulnerability in Language Override in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via the
_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_selectedLanguageId parameter.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Liferay Portal 7.4.3.112 or later.

See Also

http://www.nessus.org/u?0031daae

Plugin Details

Severity: Medium

ID: 272737

File Name: liferay_cve_2025_62264.nasl

Version: 1.2

Type: remote

Published: 11/5/2025

Updated: 11/7/2025

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2025-62264

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

CPE: cpe:/a:liferay:liferay_portal

Required KB Items: installed_sw/liferay_portal

Excluded KB Items: Settings/disable_cgi_scanning

Patch Publication Date: 10/31/2025

Vulnerability Publication Date: 10/31/2025

Reference Information

CVE: CVE-2025-62264

IAVA: 2025-A-0811