Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-07T14:57:33.054Z

Updated: 2024-08-22T19:00:34.686Z

Reserved: 2024-02-06T10:32:42.566Z

Link: CVE-2024-25145

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.657Z

cve-icon NVD

Status : Modified

Published: 2024-02-07T15:15:09.097

Modified: 2024-11-21T09:00:20.713

Link: CVE-2024-25145

cve-icon Redhat

No data.