Stored XSS Vulnerability in Liferay Portal and DXP Products
CVE-2025-62238
What is CVE-2025-62238?
A stored cross-site scripting (XSS) vulnerability exists in the Membership page within the Account Settings of Liferay Portal and DXP products. This vulnerability allows remote authenticated attackers to inject arbitrary web scripts or HTML through a specially crafted payload targeting the 'Name' text field of an account. If successfully exploited, this flaw could lead to unauthorized actions and compromise the security of affected systems. Users should ensure that they are running patched versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 7.4.13-u21 <= 7.4.13-u92
DXP 2023.Q3.1 <= 2023.Q3.8
DXP 2023.Q4.0 <= 2023.Q4.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved