Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
Moderate severity
GitHub Reviewed
Published
Nov 15, 2022
to the GitHub Advisory Database
•
Updated Aug 8, 2025
Description
Published by the National Vulnerability Database
Nov 15, 2022
Published to the GitHub Advisory Database
Nov 15, 2022
Reviewed
Aug 8, 2025
Last updated
Aug 8, 2025
A Cross-site scripting (XSS) vulnerability in the Portal Search module before 6.0.12 from Liferay Portal (7.1.0 through 7.4.2), and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the
tag
parameter.References