Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-07T14:57:33.054Z

Updated: 2024-02-07T14:57:33.054Z

Reserved: 2024-02-06T10:32:42.566Z


Link: CVE-2024-25145

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-02-07T15:15:09.097

Modified: 2024-02-15T15:10:35.503


Link: CVE-2024-25145

JSON object: View

cve-icon Redhat Information

No data.

CWE