216.73.217.172

CVE-2025-62237

· Published 10/10/2025 13:15 · Modified 10/10/2025 13:15

Labels: CVE-2025-62237 2025-10-10CVE-2025-62237CWE-79[email protected]

Essential information

Published
10/10/2025 13:15
Modified
10/10/2025 13:15
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
liferay / liferay portal cpe:2.3:a:liferay:liferay_portal:7.4.3.8-7.4.3.111:*:*:*:*:*:*:*
liferay / liferay dxp cpe:2.3:a:liferay:liferay_dxp:2023.Q4.0-2023.Q4.5:*:*:*:*:*:*:*
liferay / liferay dxp cpe:2.3:a:liferay:liferay_dxp:2023.Q3.1-2023.Q3.8:*:*:*:*:*:*:*
liferay / liferay portal cpe:2.3:a:liferay:liferay_portal:7.4:*:*:*:*:*:*:*

References