QID 731102

Date Published: 2024-01-25

QID 731102: Liferay Portal Multiple Cross-Site Scripting (XSS) Vulnerabilities

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module.

Affected Versions:
Liferay Portal 7.1.0 - 7.1.3
Liferay Portal 7.2.0 - 7.2.1
Liferay Portal 7.3.0 - 7.3.7
Liferay Portal 7.4.0 - 7.4.2
QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploitation of this vulnerability allows attackers to execute malicious scripts on the server.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731102

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-42118 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/