S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated May 14, 2025

CVE-2025-4388 Scanner

CVE-2025-4388 Scanner - Cross-Site Scripting (XSS) vulnerability in Liferay Portal

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-4388
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Portalby Liferay
7.4.0
DXPby Liferay
7.4.13
Updated Aug 5, 2026View on NVD →
Detail

Liferay Portal is a leading open-source web application framework used by organizations worldwide for developing customizable web applications and portals. It serves enterprises and public administrations to create engaging digital experiences. The platform is regularly employed for managing corporate websites, intranets, and extranets, providing a seamless way to integrate various services and applications. It's designed to enhance productivity and streamline communication within organizations. Teams across industries leverage Liferay Portal for its modularity and strong community support to tailor web solutions. Its comprehensive functionality aids in reducing development time and cost.

The reflected cross-site scripting (XSS) vulnerability in Liferay Portal's 'marketplace-app-manager-web' module poses a significant risk. XSS vulnerabilities like this one allow attackers to inject arbitrary JavaScript into web pages viewed by other users. In this particular case, the vulnerability affects numerous versions of Liferay Portal, allowing unauthenticated attackers to exploit it remotely. Such vulnerabilities are dangerous as they can lead to a range of attacks, including session hijacking or redirection to malicious sites. XSS vulnerabilities can undermine user trust and lead to unauthorized access to sensitive information.

Technically, this reflected XSS vulnerability is triggered through vulnerable endpoints in the 'marketplace-app-manager-web' module of Liferay Portal. The endpoint icon.jsp is manipulated by injecting JavaScript via the iconURL parameter. This injection allows attackers to execute arbitrary scripts in the browser of anyone accessing a crafted URL, demonstrating the lack of appropriate sanitization of input fields. The condition leading to the vulnerability is met when the server responds with a 200 HTTP status code, confirming script execution. Attackers can use this flaw to run arbitrary code to further their malicious objectives.

If exploited, this cross-site scripting (XSS) vulnerability could have severe repercussions on affected systems. It could enable attackers to execute scripts in the context of users’ browsers, leading to the unauthorized access or exfiltration of sensitive data. By compromising a user session, attackers might impersonate legitimate users or execute actions on their behalf. Furthermore, users could be redirected to malicious sites, leading to potential system compromises. Exploitation could damage an organization's reputation and result in financial losses and regulatory repercussions.

REFERENCES

Solution Advice
  • Implement strong input validation to ensure data types and input formats are restricted to acceptable values.
  • Utilize output encoding on dynamic content to correctly render data without executing injected scripts.
  • Keep software and all associated plugins updated to mitigate vulnerabilities as they are discovered.
  • Conduct regular security audits to identify and rectify potential areas of vulnerability exposure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.