SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-25152

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows…

MEDIUM 5.4EPSS 0.56%

Does this matter?

Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.

Description

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.56% probability · 45th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
liferay/liferay portal · liferay/digital experience platform
Source
security@liferay.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.