Vulnerabilities > Liferay > Digital Experience Platform > 7.3.10

DATE CVE VULNERABILITY TITLE RISK
2024-12-17 CVE-2024-11993 Unspecified vulnerability in Liferay Portal
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
network
low complexity
liferay
6.1
2022-03-03 CVE-2022-25146 Origin Validation Error vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
network
low complexity
liferay CWE-346
5.3