QID 731199
Date Published: 2024-02-26
QID 731199: Liferay Portal Privilege Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-26266)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-26266: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the Announcement widget or Alerts widget.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.13.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of the Liferay Portal in the response banner.
Successful exploitation of this vulnerability allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the Announcement widget, or Alerts widget.
CVEs related to QID 731199
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal |
|