Stored XSS vulnerability in geolocation custom fields
CVE-2024-25601
What is CVE-2024-25601?
A stored cross-site scripting vulnerability exists in the geolocation custom fields of Liferay Portal versions 7.2.0 through 7.4.2, as well as unsupported older versions. This vulnerability allows remote authenticated users to execute arbitrary web scripts or HTML by injecting malicious payloads into the name text field of a geolocation custom field. The impact can lead to unauthorized actions and loss of data integrity, affecting the overall security posture of applications utilizing these versions of Liferay Portal and Liferay DXP.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 7.3.10 <= 7.3.10-dxp-2
DXP 7.2.10 <= 7.2.10-dxp-16
Portal 7.2.0 <= 7.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved