CVE-2025-4388
Liferay Portal Reflected XSS in marketplace-app-manager-web
Record summary
CVE-2025-4388 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 7.4.13 to ≤ 7.4.13-u92 | affected |
| 2024.Q1.1 to ≤ 2024.Q1.12 | affected | ||
| 2024.Q2.0 to ≤ 2024.Q2.13 | affected | ||
| 2024.Q3.1 to ≤ 2024.Q3.13 | affected | ||
| 2024.Q4.0 to ≤ 2024.Q4.5 | affected | ||
PortalBrowse Liferay / PortalDefault status: unaffected | CVE List | 7.4.0 to ≤ 7.4.3.131 | affected |
com.liferay:com.liferay.marketplace.app.manager.webBrowse Maven / com.liferay:com.liferay.marketplace.app.manager.web | GitHub Advisory | Before 5.0.50 · Fixed in 5.0.50 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLiferay Portal - Cross-Site ScriptingCVSS 6.5
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.
Impact
Attackers can execute arbitrary JavaScript in victim browsers through the iconURL parameter in the marketplace app manager, potentially leading to session hijacking and credential theft.
Remediation
Upgrade Liferay Portal or DXP to the latest patched version that properly sanitizes the iconURL parameter.
Source: ProjectDiscovery