← Back

CVE-2023-44311

nvd nist
Published: Oct 17, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.

Affected (14)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update41
Version 7.4 update48
Version 7.4 update50
Version 7.4 update52
Version 7.4 update62
Version 7.4 update67
Version 7.4 update76
Version 7.4 update81
Version 7.4 update82
Version 7.4 update83
Version 7.4 update84
Version 7.4 update85
Version 7.4 update86
From 7.4.3.41 to 7.4.3.90

Timeline

No history available yet.