← Back

CVE-2023-33941

nvd nist
Published: May 24, 2023Modified: Jan 13, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.

Affected (13)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update41
Version 7.4 update42
Version 7.4 update43
Version 7.4 update44
Version 7.4 update45
Version 7.4 update46
Version 7.4 update47
Version 7.4 update48
Version 7.4 update49
Version 7.4 update50
Version 7.4 update51
Version 7.4 update52
From 7.4.3.41 to 7.4.3.52

Timeline

No history available yet.