Vulnerability Details CVE-2025-4599
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript into the fragment portlet URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.7%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-4599
-
cpe:2.3:a:liferay:digital_experience_platform:*
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.1
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.10
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.11
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.12
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.13
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.2
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.3
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.4
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.5
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.6
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.7
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.8
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.9
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.0
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.1
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.10
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.11
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.12
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.13
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.2
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.3
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.4
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.5
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.6
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.7
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.8
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.9
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.1
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.10
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.11
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.12
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.13
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.2
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.3
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.4
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.5
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.6
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.7
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.8
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.9
-
cpe:2.3:a:liferay:digital_experience_platform:7.4
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.100
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.101
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.102
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.103
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.104
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.105
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.106
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.107
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.108
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.109
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.110
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.111
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.112
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.113
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.114
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.115
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.116
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.117
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.118
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.119
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.120
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.121
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.122
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.123
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.124
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.125
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.126
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.127
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.128
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.129
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.130
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.61
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.62
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.63
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.64
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.65
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.66
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.67
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.68
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.69
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.70
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.71
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.72
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.73
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.74
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.75
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.76
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.77
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.78
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.79
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.80
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.81
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.82
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.83
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.84
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.85
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.86
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.87
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.88
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.89
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.90
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.91
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.92
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.94
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.95
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.96
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.97
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.98
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.99