Liferay Portal 7.4.x < 7.4.3.133 Cross-Site Scripting

medium Web App Scanning Plugin ID 114945

Synopsis

Liferay Portal 7.4.x < 7.4.3.133 Cross-Site Scripting

Description

Liferay Portal versions 7.4.x prior to 7.4.3.133 and DXP versions prior to 2024.Q1.16 or 2025.Q1.x prior to 2025.Q1.5 or 2025.Q2.x prior to 2025.Q2.0 are affected by a Cross-Site Scripting allowing an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

Solution

Upgrade to Liferay Portal version 7.4.3.133 or DXP 2024.Q1.16 or DXP 2025.Q1.5 or 2025.Q2.0 or later.

See Also

https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4576

Plugin Details

Severity: Medium

ID: 114945

Type: remote

Published: 8/13/2025

Updated: 8/13/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2025-4576

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2025-4576

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

CVSS Score Source: CVE-2025-4576

Vulnerability Information

CPE: cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/1/2025

Vulnerability Publication Date: 8/7/2025

Reference Information

CVE: CVE-2025-4576