6.1

CVE-2025-62267

Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user’s (1) First Name, (2) Middle Name, or (3) Last Name text field.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.4 Updateupdate35
LiferayDigital Experience Platform Version7.4 Updateupdate36
LiferayDigital Experience Platform Version7.4 Updateupdate37
LiferayDigital Experience Platform Version7.4 Updateupdate38
LiferayDigital Experience Platform Version7.4 Updateupdate39
LiferayDigital Experience Platform Version7.4 Updateupdate40
LiferayDigital Experience Platform Version7.4 Updateupdate41
LiferayDigital Experience Platform Version7.4 Updateupdate42
LiferayDigital Experience Platform Version7.4 Updateupdate43
LiferayDigital Experience Platform Version7.4 Updateupdate44
LiferayDigital Experience Platform Version7.4 Updateupdate45
LiferayDigital Experience Platform Version7.4 Updateupdate46
LiferayDigital Experience Platform Version7.4 Updateupdate47
LiferayDigital Experience Platform Version7.4 Updateupdate48
LiferayDigital Experience Platform Version7.4 Updateupdate49
LiferayDigital Experience Platform Version7.4 Updateupdate50
LiferayDigital Experience Platform Version7.4 Updateupdate51
LiferayDigital Experience Platform Version7.4 Updateupdate52
LiferayDigital Experience Platform Version7.4 Updateupdate53
LiferayDigital Experience Platform Version7.4 Updateupdate54
LiferayDigital Experience Platform Version7.4 Updateupdate55
LiferayDigital Experience Platform Version7.4 Updateupdate56
LiferayDigital Experience Platform Version7.4 Updateupdate57
LiferayDigital Experience Platform Version7.4 Updateupdate58
LiferayDigital Experience Platform Version7.4 Updateupdate59
LiferayDigital Experience Platform Version7.4 Updateupdate70
LiferayDigital Experience Platform Version7.4 Updateupdate71
LiferayDigital Experience Platform Version7.4 Updateupdate72
LiferayDigital Experience Platform Version7.4 Updateupdate73
LiferayDigital Experience Platform Version7.4 Updateupdate74
LiferayDigital Experience Platform Version7.4 Updateupdate75
LiferayDigital Experience Platform Version7.4 Updateupdate76
LiferayDigital Experience Platform Version7.4 Updateupdate77
LiferayDigital Experience Platform Version7.4 Updateupdate78
LiferayDigital Experience Platform Version7.4 Updateupdate79
LiferayDigital Experience Platform Version7.4 Updateupdate80
LiferayDigital Experience Platform Version7.4 Updateupdate81
LiferayDigital Experience Platform Version7.4 Updateupdate82
LiferayDigital Experience Platform Version7.4 Updateupdate83
LiferayDigital Experience Platform Version7.4 Updateupdate84
LiferayDigital Experience Platform Version7.4 Updateupdate85
LiferayDigital Experience Platform Version7.4 Updateupdate86
LiferayDigital Experience Platform Version7.4 Updateupdate87
LiferayDigital Experience Platform Version7.4 Updateupdate88
LiferayDigital Experience Platform Version7.4 Updateupdate89
LiferayDigital Experience Platform Version7.4 Updateupdate90
LiferayDigital Experience Platform Version7.4 Updateupdate91
LiferayDigital Experience Platform Version7.4 Updateupdate92
LiferayDigital Experience Platform Version2023.q3.1
LiferayDigital Experience Platform Version2023.q3.2
LiferayDigital Experience Platform Version2023.q3.3
LiferayDigital Experience Platform Version2023.q3.4
LiferayDigital Experience Platform Version2023.q3.5
LiferayDigital Experience Platform Version2023.q3.6
LiferayDigital Experience Platform Version2023.q3.7
LiferayDigital Experience Platform Version2023.q3.8
LiferayDigital Experience Platform Version2023.q3.9
LiferayDigital Experience Platform Version2023.q3.10
LiferayDigital Experience Platform Version2023.q4.0
LiferayDigital Experience Platform Version2023.q4.1
LiferayDigital Experience Platform Version2023.q4.2
LiferayDigital Experience Platform Version2023.q4.3
LiferayDigital Experience Platform Version2023.q4.4
LiferayDigital Experience Platform Version2023.q4.5
LiferayDigital Experience Platform Version2023.q4.6
LiferayDigital Experience Platform Version2023.q4.7
LiferayDigital Experience Platform Version2023.q4.8
LiferayDigital Experience Platform Version2023.q4.9
LiferayDigital Experience Platform Version2023.q4.10
LiferayLiferay Portal Version >= 7.4.3.35 < 7.4.3.112
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 4.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.