Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script console
Moderate severity
GitHub Reviewed
Published
Mar 4, 2022
to the GitHub Advisory Database
•
Updated Jul 15, 2025
Description
Published by the National Vulnerability Database
Mar 3, 2022
Published to the GitHub Advisory Database
Mar 4, 2022
Reviewed
Jul 15, 2025
Last updated
Jul 15, 2025
Liferay Server Admin Web before 4.0.12 from Liferay Portal v7.3.2 and below and Liferay DXP v7.0 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the script console under the Server module.
References