QID 731199

Date Published: 2024-02-26

QID 731199: Liferay Portal Privilege Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-26266)

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

CVE-2024-26266: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the Announcement widget or Alerts widget.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.13.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of the Liferay Portal in the response banner.

Successful exploitation of this vulnerability allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the Announcement widget, or Alerts widget.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released a patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731199

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26266