QID 731142
Date Published: 2024-02-08
QID 731142: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-25145)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-25145: Stored cross-site scripting (XSS) vulnerability found in the Portal Search module's Search Result app in Liferay Portal.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.11.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
CVEs related to QID 731142
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-25145 |
|