Liferay Portal and Liferay DXP Vulnerable to XSS via the Sharing Module
Moderate severity
GitHub Reviewed
Published
Nov 15, 2022
to the GitHub Advisory Database
•
Updated Aug 8, 2025
Description
Published by the National Vulnerability Database
Nov 15, 2022
Published to the GitHub Advisory Database
Nov 15, 2022
Reviewed
Aug 8, 2025
Last updated
Aug 8, 2025
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification before 3.0.9 from Liferay Portal (7.2.1 through 7.4.2), and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
References