GHSA-m4g9-5mg6-gfr3

Suggest an improvement
Source
https://github.com/advisories/GHSA-m4g9-5mg6-gfr3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-m4g9-5mg6-gfr3/GHSA-m4g9-5mg6-gfr3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m4g9-5mg6-gfr3
Aliases
Published
2025-10-10T15:31:28Z
Modified
2025-10-11T01:27:28Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal Commerce is vulnerable to XSS through account "name" field
Details

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-11T00:33:05Z",
    "nvd_published_at":  "2025-10-10T13:15:48Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.commerce:com.liferay.commerce.order.web

Package

Name
com.liferay.commerce:com.liferay.commerce.order.web
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.commerce/com.liferay.commerce.order.web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.29
Fixed
5.0.101

Affected versions

5.*
5.0.29
5.0.30
5.0.31
5.0.32
5.0.33
5.0.34
5.0.35
5.0.36
5.0.37
5.0.38
5.0.39
5.0.40
5.0.41
5.0.42
5.0.43
5.0.44
5.0.45
5.0.46
5.0.47
5.0.48
5.0.49
5.0.50
5.0.51
5.0.52
5.0.53
5.0.54
5.0.55
5.0.56
5.0.57
5.0.58
5.0.59
5.0.60
5.0.61
5.0.62
5.0.63
5.0.64
5.0.65
5.0.66
5.0.67
5.0.68
5.0.69
5.0.70
5.0.71
5.0.72
5.0.73
5.0.74
5.0.75
5.0.76
5.0.77
5.0.78
5.0.79
5.0.80
5.0.81
5.0.82
5.0.83
5.0.84
5.0.85
5.0.86
5.0.87
5.0.88
5.0.89
5.0.90
5.0.91
5.0.92
5.0.93
5.0.94
5.0.95
5.0.96
5.0.97
5.0.98
5.0.99
5.0.100

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-m4g9-5mg6-gfr3/GHSA-m4g9-5mg6-gfr3.json"