Listen to this Post
This CVE describes a self cross-site scripting vulnerability within the Knowledge Base editing interface of Liferay Portal and Liferay DXP. The flaw exists in the handling of attachment filenames. A remote attacker can craft a malicious filename containing a script payload. When this specially crafted filename is uploaded as an attachment to a Knowledge Base , the script is not properly neutralized. The vulnerability is “self” because the attacker must trick themselves into uploading the file and then viewing the edit page where the payload renders, primarily demonstrating the flaw’s existence rather than enabling direct attacks on other users without further interaction.
Platform: Liferay Portal/DXP
Version: 7.4.0-7.4.3.101
Vulnerability: Self XSS
Severity: Low
date: 2025-10-23
Prediction: Patch available
What Undercode Say:
Example payload for filename
mv legitimate_file.pdf "legit_file<svg onload=alert('XSS')>.pdf"
Checking Liferay version via API or file system
find /opt/liferay -name "portal-impl.jar" -exec grep -l "Bundle-Version" {} \;
<!-- Payload rendered in edit page --> <a href="/documents/kb/.../attachment_name<scrIPT>alert(1)</scrIPT>">attachment_name<scrIPT>alert(1)</scrIPT></a>
How Exploit:
Craft malicious filename.
Upload as KB attachment.
View edit page.
Protection from this CVE
Apply patch 5.0.109.
Implement input sanitization.
Escape output in UI.
Impact:
Limited security impact.
Proof-of-concept execution.
No direct user compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

