Liferay Portal Vulnerable to XSS in the Object Module
Moderate severity
GitHub Reviewed
Published
Oct 19, 2022
to the GitHub Advisory Database
•
Updated Jul 16, 2025
Package
Affected versions
< 1.0.99
Patched versions
1.0.99
Description
Published by the National Vulnerability Database
Oct 18, 2022
Published to the GitHub Advisory Database
Oct 19, 2022
Reviewed
Jul 16, 2025
Last updated
Jul 16, 2025
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Object Web before 1.0.99 from Liferay Portal (7.4.3.4 through 7.4.3.36) allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's
Label
text field.References