Stored XSS Vulnerability in Liferay Portal and DXP Products
CVE-2025-62238

4.8MEDIUM

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-62238?

A stored cross-site scripting (XSS) vulnerability exists in the Membership page within the Account Settings of Liferay Portal and DXP products. This vulnerability allows remote authenticated attackers to inject arbitrary web scripts or HTML through a specially crafted payload targeting the 'Name' text field of an account. If successfully exploited, this flaw could lead to unauthorized actions and compromise the security of affected systems. Users should ensure that they are running patched versions to mitigate this risk.

Affected Version(s)

DXP 7.4.13-u21 <= 7.4.13-u92

DXP 2023.Q3.1 <= 2023.Q3.8

DXP 2023.Q4.0 <= 2023.Q4.5

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

foobar7
.
CVE-2025-62238 : Stored XSS Vulnerability in Liferay Portal and DXP Products