Skip to content

Commit 07fef02

Browse files
1 parent d7c227b commit 07fef02

File tree

3 files changed

+5
-4
lines changed

3 files changed

+5
-4
lines changed

advisories/github-reviewed/2025/09/GHSA-66x6-8jgv-qpfh/GHSA-66x6-8jgv-qpfh.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-66x6-8jgv-qpfh",
4-
"modified": "2025-09-10T20:51:58Z",
4+
"modified": "2025-12-20T02:56:22Z",
55
"published": "2025-09-10T18:30:16Z",
66
"aliases": [
77
"CVE-2025-43785"
88
],
99
"summary": "Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting",
10-
"details": "Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.",
10+
"details": "A stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

advisories/github-reviewed/2025/09/GHSA-9p7x-8c57-4pqv/GHSA-9p7x-8c57-4pqv.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,7 @@
105105
],
106106
"database_specific": {
107107
"cwe_ids": [
108+
"CWE-203",
108109
"CWE-208"
109110
],
110111
"severity": "MODERATE",

advisories/github-reviewed/2025/09/GHSA-fvp7-jj9m-3qpf/GHSA-fvp7-jj9m-3qpf.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-fvp7-jj9m-3qpf",
4-
"modified": "2025-09-12T21:08:53Z",
4+
"modified": "2025-12-20T02:55:23Z",
55
"published": "2025-09-10T21:30:19Z",
66
"aliases": [
77
"CVE-2025-43784"
88
],
99
"summary": "Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data",
10-
"details": "Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entry information via the API Builder.",
10+
"details": "An Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entry information via the API Builder.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

0 commit comments

Comments
 (0)