GHSA-8mgf-rgg5-w38q
MODERATECVE-2025-62263Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page
- Affected
- >= 2.0.0, < 2.0.108
- Fixed in
- 2.0.108
- Weakness
- CWE-79
- Published
- 2025-10-27
- Source
- github