Self Cross-site Scripting Vulnerability in Liferay Portal and DXP Products
CVE-2025-62255
What is CVE-2025-62255?
A self cross-site scripting (XSS) vulnerability has been identified in the Liferay Portal and DXP products. This vulnerability affects versions from 7.4.0 to 7.4.3.101 and older unsupported versions, as well as Liferay DXP versions 2023.Q3.1 to 2023.Q3.5. It allows remote attackers to exploit the flaw by injecting arbitrary web scripts or HTML code through a specially crafted payload in an attachment's filename on the Knowledge Base article edit page. This could potentially lead to unwanted actions executed in the context of the user’s browser, posing significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 7.3.10 <= 7.3.10-u34
DXP 7.4.13 <= 7.4.13-u92
DXP 2023.Q3.1 <= 2023.Q3.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved