Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page
Critical severity
GitHub Reviewed
Published
Oct 17, 2023
to the GitHub Advisory Database
•
Updated Aug 8, 2025
Description
Published by the National Vulnerability Database
Oct 17, 2023
Published to the GitHub Advisory Database
Oct 17, 2023
Reviewed
Aug 8, 2025
Last updated
Aug 8, 2025
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page before 2.0.86 from Liferay Portal (7.4.3.4 through 7.4.3.85), and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the
_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect
parameter.References