← Back

CVE-2023-44309

nvd nist
Published: Oct 17, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.

Affected (10)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4
Version 7.4 update1
Version 7.4 update21
Version 7.4 update34
Version 7.4 update36
Version 7.4 update41
Version 7.4 update48
Version 7.4 update50
Version 7.4 update52
From 7.4.2 to 7.4.3.53

Timeline

No history available yet.