CVE-2025-62264

MEDIUM

Liferay Digital Experience Platform < 7.4.3.112 - XSS

Title source: rule
STIX 2.1

Description

Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_selectedLanguageId` parameter.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
com.liferay.portal/release.portal.bom 7.4.3.8 - 7.4.3.112-ga112Maven
liferay/digital_experience_platform 7.4 update10 (49 CPE variants)
Published Oct 31, 2025
Tracked Since Feb 18, 2026