Loading HuntDB...

GHSA-4hxr-28mv-q729

GitHub Security Advisory

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field

Affected Packages

Maven com.liferay.portal:release.portal.bom
Affected versions: 7.1.0 (fixed in 7.4.3.39)
Maven com.liferay.portal:release.dxp.bom
Affected versions: 7.1 (fixed in 7.4.13.u39)

Related CVEs

Key Information

GHSA ID
GHSA-4hxr-28mv-q729
Published
December 17, 2024 9:30 PM
Last Modified
January 28, 2025 10:26 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.liferay.portal:release.portal.bom
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.