Liferay Portal 7.4.x < 7.4.3.132 Cross-Site Scripting

medium Web App Scanning Plugin ID 114944

Synopsis

Liferay Portal 7.4.x < 7.4.3.132 Cross-Site Scripting

Description

Liferay Portal versions 7.4.x prior to 7.4.3.132 and DXP versions prior to 2024.Q1.13 or 2024.Q2 prior to 2024.Q4.6 are affected by a Cross-Site Scripting allowing an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

Solution

Upgrade to Liferay Portal version 7.4.3.132 or DXP 2024.Q1.13 or DXP 2024.Q4.6 or later.

See Also

https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4388

Plugin Details

Severity: Medium

ID: 114944

Type: remote

Published: 8/13/2025

Updated: 8/13/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2025-4388

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2025-4388

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

CVSS Score Source: CVE-2025-4388

Vulnerability Information

CPE: cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/18/2025

Vulnerability Publication Date: 3/19/2025

Reference Information

CVE: CVE-2025-4388