Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay.portal/release.dxp.bom
  4. ›
  5. CVE-2025-3760

CVE-2025-3760: Liferay Cross-site Scripting vulnerability

April 17, 2025

A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.

References

  • github.com/advisories/GHSA-qhp6-vp7c-g7xp
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-3760
  • nvd.nist.gov/vuln/detail/CVE-2025-3760

Code Behaviors & Features

Detect and mitigate CVE-2025-3760 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.2.10.fp1 up to 7.2.10.fp20, all versions starting from 7.3.10.ep1 up to 7.3.10.u36, all versions starting from 7.4.13.u1 up to 7.4.13.u92, all versions starting from 2023.Q3.1 up to 2023.Q3.10, all versions starting from 2023.Q4.0 up to 2023.Q4.10, all versions starting from 2024.Q1.1 before 2024.Q1.13, all versions starting from 2024.Q2.0 up to 2024.Q2.13, all versions starting from 2024.Q3.1 before 2024.Q3.10, all versions starting from 2024.Q4.1 before 2025.Q1.0, all versions starting from 7.3.10.0 up to 7.3.10.3, all versions starting from 7.2.10 up to 7.2.10.8, version 7.4.13

Fixed versions

  • 2024.Q1.13
  • 2024.Q3.10
  • 2025.Q1.0

Solution

Upgrade to versions 2024.Q1.13, 2024.Q3.10, 2025.Q1.0 or above.

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

maven/com.liferay.portal/release.dxp.bom/CVE-2025-3760.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 00:15:12 +0000.