
Reflected XSS in Liferay Portal → Data Exposure (CVE-2025-4388) (Based on a real disclosed vulnerability listed in HackerOne’s CVE discovery data) POC → 1. During testing of Liferay Portal 7.4, found that certain parameters were reflected in the HTML response without proper encoding 2. Constructed a malicious input payload to be included in a URL 3. Triggered execution by having the victim click the crafted link 4. The browser executed the injected script via the reflected content 5. This allowed JavaScript execution in the victim’s session context 6. With accessible DOM and cookies, potential data exposure or session hijack was possible Learning → - Reflected XSS remains effective when inputs aren’t properly escaped - Always apply contextual encoding on user-controlled data - Even “old school” bugs persist in modern apps and can still lead to higher impact events (e.g., session exposure) #infosec #hacking #bugbounty #bugbountytips
Post summary
The post discloses a reflected XSS vulnerability in Liferay Portal 7.4, provides a clear Proof of Concept, but does not mention any exploit tool, active exploitation, patch, or false‑positive claims.

