Record summary

CVE-2025-4388 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.4.13 to ≤ 7.4.13-u92affected
2024.Q1.1 to ≤ 2024.Q1.12affected
2024.Q2.0 to ≤ 2024.Q2.13affected
2024.Q3.1 to ≤ 2024.Q3.13affected
2024.Q4.0 to ≤ 2024.Q4.5affected

Default status: unaffected

CVE List7.4.0 to ≤ 7.4.3.131affected

com.liferay:com.liferay.marketplace.app.manager.web

Browse Maven / com.liferay:com.liferay.marketplace.app.manager.web
GitHub AdvisoryBefore 5.0.50 · Fixed in 5.0.50affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLiferay Portal - Cross-Site ScriptingCVSS 6.5

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

Impact

Attackers can execute arbitrary JavaScript in victim browsers through the iconURL parameter in the marketplace app manager, potentially leading to session hijacking and credential theft.

Remediation

Upgrade Liferay Portal or DXP to the latest patched version that properly sanitizes the iconURL parameter.

WeaknessesCWE-79
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2025liferaymarketplacexssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Shodan: html:"liferayPortalCSS"
FOFA: body="liferayPortalCSS"

Source: ProjectDiscovery

References

4