Liferay DXP 7.4 Update 25

CPE Details

Liferay DXP 7.4 Update 25
7.4
2022-09-23
11h33 +00:00
2022-09-26
13h45 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:liferay:dxp:7.4:update_25:*:*:*:*:*:*

Informations

Vendor

liferay

Product

dxp

Version

7.4

Update

update_25

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-25144 2024-02-08 03h25 +00:00 The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
6.5
Medium
CVE-2022-38901 2022-10-18 22h00 +00:00 A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
5.4
Medium
CVE-2022-42114 2022-10-17 22h00 +00:00 A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
5.4
Medium
CVE-2022-38512 2022-09-21 22h17 +00:00 The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
6.5
Medium
CVE-2022-39975 2022-09-21 21h35 +00:00 The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
4.3
Medium