A vulnerability was found in Liferay Portal and DXP. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Expando Module. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-25601. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.