← Back

CVE-2023-42497

nvd nist
Published: Oct 17, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.

Affected (18)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4
Version 7.4 update1
Version 7.4 update21
Version 7.4 update34
Version 7.4 update36
Version 7.4 update41
Version 7.4 update48
Version 7.4 update50
Version 7.4 update52
Version 7.4 update62
Version 7.4 update67
Version 7.4 update76
Version 7.4 update81
Version 7.4 update82
Version 7.4 update83
Version 7.4 update84
Version 7.4 update85
From 7.4.3.4 to 7.4.3.86

Timeline

No history available yet.