Reflected XSS Vulnerabilities in Liferay Portal and DXP Products
CVE-2023-44311
9.6CRITICAL
What is CVE-2023-44311?
Multiple reflected XSS vulnerabilities exist in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class within Liferay Portal and DXP. These vulnerabilities allow remote attackers to exploit the system by injecting arbitrary web script or HTML through specific parameters, stemming from an incomplete fix in a previous vulnerability. This can potentially lead to unauthorized actions or information disclosure, emphasizing the importance of timely updates and security measures to mitigate these risks.
Affected Version(s)
DXP 7.4.13.u41 <= 7.4.13.u89
Portal 7.4.3.41 <= 7.4.3.89