Skip to content

Commit 613fd27

Browse files
1 parent 1e367c6 commit 613fd27

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed

advisories/github-reviewed/2025/10/GHSA-893r-jr58-3hxr/GHSA-893r-jr58-3hxr.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-893r-jr58-3hxr",
4-
"modified": "2025-10-09T15:32:05Z",
4+
"modified": "2025-12-17T00:15:50Z",
55
"published": "2025-10-08T15:32:27Z",
66
"aliases": [
77
"CVE-2025-43829"
88
],
99
"summary": "Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file",
10-
"details": "Stored Cross-Site Scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a SVG file.",
10+
"details": "There is a Stored Cross-Site Scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a SVG file.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

advisories/github-reviewed/2025/10/GHSA-fjrp-77f3-43xj/GHSA-fjrp-77f3-43xj.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-fjrp-77f3-43xj",
4-
"modified": "2025-10-09T15:33:32Z",
4+
"modified": "2025-12-17T00:14:26Z",
55
"published": "2025-10-08T15:32:26Z",
66
"aliases": [
77
"CVE-2025-43821"
88
],
9-
"summary": "Liferay Portal is vulnerable to XXS through its Commerce Product's Name text field",
10-
"details": "Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.",
9+
"summary": "Liferay Portal is vulnerable to XSS through its Commerce Product's Name text field",
10+
"details": "Cross-site Scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

0 commit comments

Comments
 (0)