CVE-2025-4388
MEDIUM NUCLEILiferay Digital Experience Platform < 2024.Q1.13 - XSS
Title source: ruleDescription
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.
Nuclei Templates (1)
Liferay Portal - Cross-Site Scripting
MEDIUMVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan:
html:"liferayPortalCSS"
FOFA:
body="liferayPortalCSS"
Scores
CVSS v3
6.1
EPSS
0.2506
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (4)
com.liferay/com.liferay.marketplace.app.manager.web
0 - 5.0.50Maven
liferay/digital_experience_platform
7.4
liferay/digital_experience_platform
2024.Q1.1 - 2024.Q1.13
liferay/liferay_portal
7.4.0 - 7.4.3.132
Published
May 06, 2025
Tracked Since
Feb 18, 2026