Liferay Vulnerabilities and Affected Products
Vulnerabilities associated with liferay_portal.
Products
Clear product- DXP210 vulnerabilities
- Portal208 vulnerabilities
- digital_experience_platform7 vulnerabilities
- liferay_portal2 vulnerabilities
- Liferay Portal1 vulnerability
- liferay_enterprise_portal1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-25152CRITICAL | Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site ScriptingStored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment. CWE-79Feb 21, 2024 | CVSS9.0v3.1 | EPSS0.558% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-25607HIGH | Liferay Portal defaults to a low work factor for the default password hashing algorithmThe default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes. CWE-916Feb 20, 2024 | CVSS8.1v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |