legacy-knowledge-base
公開されました Sep. 10, 2025

Liferay Marketplace App Manager Web XSS Vulnerability (CVE-2025-4388)

written-by

Stanley Huang

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

Issue

  • A reflected cross-site scripting (XSS) vulnerability (CVE-2025-4388) in /o/marketplace-app-manager-web/icon.jsp allows a remote non-authenticated attacker to inject JavaScript into the modules/apps/marketplace/marketplace-app-manager-web module.

Environment

  • 2024.Q1.8

Resolution

  • This issue has been addressed in 2024.Q1.13.
  • For earlier Liferay versions, please request a hotfix from Support if necessary.

Additional Information

did-this-article-resolve-your-issue

legacy-knowledge-base