/Vulnerability Library

Liferay Portal & DXP - Cross-Site Scripting

CVE-2025-4576
Verified

Description

Liferay Portal 7.4.0 through 7.4.3.133 and Liferay DXP 2024.Q1.1 through 2025.Q1.4 contain a reflected XSS caused by improper sanitization in entry_cover_image_caption.jsp, letting remote non-authenticated attackers inject JavaScript.

Severity

Medium

CVSS Score

6.1

Exploit Probability

1%

Published Date

March 26, 2026

Template Author

xtr0nix

CVE-2025-4576.yaml
6.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2025-4576
CWE ID:
cwe-79

References

https://github.com/advisories/GHSA-6qcg-28jh-hm7rhttps://nvd.nist.gov/vuln/detail/CVE-2025-4576

Remediation Steps

Update to the latest available version beyond 7.4.3.133 and 2025.Q1.4.