Moderate severityNVD Advisory· Published Oct 10, 2025· Updated Oct 10, 2025
CVE-2025-62237
CVE-2025-62237
Description
Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.commerce:com.liferay.commerce.order.webMaven | >= 5.0.29, < 5.0.101 | 5.0.101 |
Affected products
3Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.