CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It may be remotely exploitable.
CVE
CVE-2025-62237
Severity
MEDIUM
CVSS
5.4
EPSS
0.21%
Original NVD Description
Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.
Related CVEs
Other vulnerabilities affecting the same vendor(s)