GHSA-vg6h-g5mr-9hgv

Suggest an improvement
Source
https://github.com/advisories/GHSA-vg6h-g5mr-9hgv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-vg6h-g5mr-9hgv/GHSA-vg6h-g5mr-9hgv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vg6h-g5mr-9hgv
Aliases
Published
2025-09-16T00:30:21Z
Modified
2025-09-16T19:57:24Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Stored Cross-site Scripting vulnerability
Details

Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/ API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35 allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-16T19:22:06Z",
    "nvd_published_at":  "2025-09-15T22:15:34Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.workspace:com.liferay.ticket.workspace

Package

Name
com.liferay.workspace:com.liferay.ticket.workspace
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.workspace/com.liferay.ticket.workspace

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20240122.0632

Affected versions

20231017.*
20231017.1700
20231024.*
20231024.2216
20231102.*
20231102.0315
20231108.*
20231108.1327
20231108.1457
20231115.*
20231115.1308
20231115.2217
20231116.*
20231116.1424
20231116.2404
20231119.*
20231119.2314
20231122.*
20231122.1834
20231202.*
20231202.1425
20231204.*
20231204.1115
20231208.*
20231208.2331
20231215.*
20231215.2426
20231220.*
20231220.2042
20231221.*
20231221.0813
20231224.*
20231224.1556
20231224.1834
20240106.*
20240106.1638
20240107.*
20240107.1156
20240110.*
20240110.2051

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-vg6h-g5mr-9hgv/GHSA-vg6h-g5mr-9hgv.json"