Stored Cross-Site Scripting Vulnerabilities in Liferay Portal and DXP
CVE-2023-44309

9CRITICAL

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
17 October 2023

What is CVE-2023-44309?

Multiple stored cross-site scripting vulnerabilities exist within Liferay Portal and Liferay DXP. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML into linked source assets, leveraging crafted payloads injected into any non-HTML field. Affected versions include Liferay Portal 7.4.2 through 7.4.3.53 and Liferay DXP 7.4 prior to update 54, emphasizing the need for immediate attention to maintain the security integrity of web applications.

Affected Version(s)

DXP 7.4.13 <= 7.4.13.u53

Portal 7.4.2 <= 7.4.3.53

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.