Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-21T01:16:21.256Z

Updated: 2024-08-01T23:36:21.759Z

Reserved: 2024-02-06T10:32:42.567Z

Link: CVE-2024-25147

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.759Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-21T02:15:29.750

Modified: 2024-02-22T19:07:37.840

Link: CVE-2024-25147

cve-icon Redhat

No data.