A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
2022-10-18T21:15:16.203
2025-05-13T18:17:51.450
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | liferay | digital_experience_platform | < 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | digital_experience_platform | 7.2 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | dxp | 7.4 | Yes |
Application | liferay | liferay_portal | < 7.4.3.25 | Yes |