CVE-2025-62255 LOW

CVE-2025-62255

Vendor Liferay
Product Portal
Weakness CWE-79 · XSS
Published October 23, 2025
Last update October 23, 2025

CVSS base score

2.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an attachment's filename.

Key dates

02Disclosure timeline

October 23, 2025 CVE published
October 23, 2025 Record updated

Related vulnerabilities

04Related CVE