CVE-2024-11993
📊 4.6 MEDIUM⚡ 0.1%🎯 0 exploits
📅 Published Dec 17, 2024
📋 Status: Modified
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
CVSS v3.1 • NVD
🎯 Affected Products & Systems
41 product configurations affected
Filter by type:
| Type | Vendor | Product | Version Range | Status | CPE String |
|---|---|---|---|---|---|
📱App | liferay | liferay portal | ≥ 7.1.0 ∧ < 7.4.3.39 | Vulnerable | cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
📱App | liferay | digital experience platform | ≥ 7.1 ∧ < 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:* |
📱App | liferay | digital experience platform | 7.4 | Vulnerable | cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:* |
📱
VulnerableApplication
Version: ≥ 7.1.0 ∧ < 7.4.3.39
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
📱
VulnerableApplication
Version: ≥ 7.1 ∧ < 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:*
📱
VulnerableApplication
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:*
41 products•scroll for more
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔍 Technical Details
Analysis Status
ModifiedCVSS Details
4.6 (MEDIUM)v4.0
Source: [email protected]
EPSS Details
0.1% (Minimal)22.7th percentile
Last updated: Oct 31, 2025
Exploitation probability within 30 days
Published Date
Dec 17, 2024 (10 months ago)
Last Modified
Mar 28, 2025 (7 months ago)
Security Weaknesses1
CWE-79
References2
NVDadvisory