Reflected XSS Vulnerabilities in Liferay Portal and DXP Products
CVE-2023-44311

9.6CRITICAL

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
17 October 2023

What is CVE-2023-44311?

Multiple reflected XSS vulnerabilities exist in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class within Liferay Portal and DXP. These vulnerabilities allow remote attackers to exploit the system by injecting arbitrary web script or HTML through specific parameters, stemming from an incomplete fix in a previous vulnerability. This can potentially lead to unauthorized actions or information disclosure, emphasizing the importance of timely updates and security measures to mitigate these risks.

Affected Version(s)

DXP 7.4.13.u41 <= 7.4.13.u89

Portal 7.4.3.41 <= 7.4.3.89

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.