CVE-2025-4388PoC(liferay / digital_experience_platform)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • digital_experience_platform
  • liferay_portal

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
digital_experience_platformliferay_portal

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-05: 1Technical Details · 2026-02-05: 102-0502-06
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-051
PoC1
2026-02-061
General1
Full discourse2 posts
  • VIEH Group@viehgroup
    PoC

    Reflected XSS in Liferay Portal → Data Exposure (CVE-2025-4388) (Based on a real disclosed vulnerability listed in HackerOne’s CVE discovery data) POC → 1. During testing of Liferay Portal 7.4, found that certain parameters were reflected in the HTML response without proper encoding 2. Constructed a malicious input payload to be included in a URL 3. Triggered execution by having the victim click the crafted link 4. The browser executed the injected script via the reflected content 5. This allowed JavaScript execution in the victim’s session context 6. With accessible DOM and cookies, potential data exposure or session hijack was possible Learning → - Reflected XSS remains effective when inputs aren’t properly escaped - Always apply contextual encoding on user-controlled data - Even “old school” bugs persist in modern apps and can still lead to higher impact events (e.g., session exposure) #infosec #hacking #bugbounty #bugbountytips

    Post summary

    The post discloses a reflected XSS vulnerability in Liferay Portal 7.4, provides a clear Proof of Concept, but does not mention any exploit tool, active exploitation, patch, or false‑positive claims.

    13022111.0K
    5.9K followersView on X
  • VulnTracker@vuln_tracker
    General

    @viehgroup You now can see the full details about CVE-2025-4388 from https://vulntracker.io/cves/CVE-2025-43888

    Post summary

    The tweet directs users to a link for more information on CVE-2025-4388 but contains no substantive details itself.

    0000033
    333 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appliferaydigital_experience_platform---
Appliferaydigital_experience_platform7.4--
Appliferayliferay_portal---

Explore more