CRITICAL
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter
Published Oct 17, 2023
9.6
CRITICALCVSS 3.1
EPSS 0.46%
Description
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
Affected products
-
- Version 7.4.13StatusaffectedConstraints<=7.4.13.u85
- Version
-
- Version 7.4.3.4StatusaffectedConstraints<=7.4.3.85
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
OR
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- ≥ 7.4.3.4 · < 7.4.3.86
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-46936 Advisory
- https://github.com/advisories/GHSA-w2g3-j73q-7qv7 Advisory
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42497 vendor-advisoryVendor Advisory
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42497?p_r_p_assetEntryId=122124913&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D122124913%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse
- https://nvd.nist.gov/vuln/detail/CVE-2023-42497
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Liferay
Published Oct 17, 2023
Updated Sep 13, 2024
Reserved Sep 11, 2023
Link CVE-2023-42497
CISA Vulnrichment
Updated Sep 13, 2024
ENISA EUVD
EUVD-2023-46936 GHSA-W2G3-J73Q-7QV7 Assigner Liferay
Published Oct 17, 2023
Updated Sep 13, 2024
Exploited since n/a
Link EUVD-2023-46936