{"id":"CVE-2025-62263","aliases":["GHSA-8mgf-rgg5-w38q"],"url":"https://o3.security/vulnerability/CVE-2025-62263","summary":"Liferay Portal Vulnerable to Cross-Site Scripting","details":"Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page.\n\nMultiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Organization’s “Name” text field to (1) view account page, (2) view account organization page, or (3) select account organization page.","published":"2025-10-27T20:15:54.603Z","modified":"2026-09-05T03:30:41.712603536Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.liferay:com.liferay.account.admin.web","fixedVersion":"2.0.108"}],"fix":{"url":"https://github.com/liferay/liferay-portal/commit/13571a47fd59dcb5f52d938df82960b3421b51b2","label":"liferay/liferay-portal@13571a4"},"references":[{"type":"ADVISORY","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62263"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62263"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/13571a47fd59dcb5f52d938df82960b3421b51b2"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/842c142d87d0187ea2af19ee79dd1694fd46d72b"},{"type":"PACKAGE","url":"https://github.com/liferay/liferay-portal"},{"type":"WEB","url":"https://liferay.atlassian.net/browse/LPE-17861"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-05T03:30:41.712603536Z"}}