MEDIUM
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field
Published May 24, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.53%
Description
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
Affected products
-
Affected
- ≥ 7.3.10, ≤ 7.3.10.u23
- ≥ 7.4.13, ≤ 7.4.13.u68
-
Affected
- ≥ 7.3.4, ≤ 7.4.3.68
OR
- ≥ 7.4.0 · ≤ 7.4.3.68
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- ≥ 7.3.4 · ≤ 7.3.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1596 Advisory
- https://github.com/advisories/GHSA-pfwc-4frf-4gf8 Advisory
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33944 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-33944
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1596 | Advisory | |
| https://github.com/advisories/GHSA-pfwc-4frf-4gf8 | Advisory | |
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33944 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-33944 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Liferay
Published May 24, 2023
Updated Oct 22, 2024
Reserved May 24, 2023
Link CVE-2023-33944
CISA Vulnrichment
Updated Oct 22, 2024
Red Hat
No data
GitHub
Link GHSA-PFWC-4FRF-4GF8