CVE-2025-4604

EUVD-2025-23557
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
liferaydigital_experience_platform
2024.q1.1 ≤
𝑥
≤ 2024.q1.19
liferaydigital_experience_platform
2024.q2.0 ≤
𝑥
≤ 2024.q2.13
liferaydigital_experience_platform
2024.Q3.0 ≤
𝑥
≤ 2024.Q3.13
liferaydigital_experience_platform
2024.q4.0 ≤
𝑥
≤ 2024.q4.7
liferaydigital_experience_platform
2025.q1.0 ≤
𝑥
≤ 2025.q1.15
liferaydigital_experience_platform
7.4
liferaydigital_experience_platform
7.4:update80
liferaydigital_experience_platform
7.4:update81
liferaydigital_experience_platform
7.4:update82
liferaydigital_experience_platform
7.4:update83
liferaydigital_experience_platform
7.4:update84
liferaydigital_experience_platform
7.4:update85
liferaydigital_experience_platform
7.4:update86
liferaydigital_experience_platform
7.4:update87
liferaydigital_experience_platform
7.4:update88
liferaydigital_experience_platform
7.4:update89
liferaydigital_experience_platform
7.4:update90
liferaydigital_experience_platform
7.4:update91
liferaydigital_experience_platform
7.4:update92
liferayliferay_portal
7.4.3.80 ≤
𝑥
≤ 7.4.3.132
𝑥
= Vulnerable software versions