CVE-2024-11993

📊 4.6 MEDIUM0.1%🎯 0 exploits
📅 Published Dec 17, 2024
📋 Status: Modified

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field

🎯 Affected Products & Systems

41 product configurations affected

Filter by type:
📱
Application
Vulnerable
Version: ≥ 7.1.0 ∧ < 7.4.3.39
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Vulnerable
Version: ≥ 7.1 ∧ < 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:*
41 productsscroll for more
Metrics
4.6 MEDIUMCVSS v4.0[email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

🔍 Technical Details

Analysis Status
Modified
CVSS Details
4.6 (MEDIUM)v4.0
EPSS Details
0.1% (Minimal)22.7th percentile
Last updated: Oct 31, 2025
Exploitation probability within 30 days
Published Date
Dec 17, 2024 (10 months ago)
Last Modified
Mar 28, 2025 (7 months ago)
Security Weaknesses1
References2