CVE-2023-42629
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
Affected (19)
Products: Liferay: Digital Experience Platform, Liferay Portal
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.4 | |
| From 7.4.2 to 7.4.3.88 |
References (4)
Source: security@liferay.com
Vendor Advisory
Source: security@liferay.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.