Stored XSS vulnerability in Liferay Portal
CVE-2023-47795
What is CVE-2023-47795?
The vulnerability in Liferay Portal and DXP allows for a stored cross-site scripting (XSS) attack through the Document and Media widget. This flaw permits remote authenticated users to inject malicious web scripts or HTML content via a specially crafted payload inserted into a document's 'Title' text field. The affected versions include Liferay Portal 7.4.3.18 up to 7.4.3.101 and Liferay DXP 2023.Q3 before patch 6, exposing systems to potential breaches and unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 2023.q3.1 <= 2023.q3.5
DXP 7.4.13.u18 <= 7.4.13.u92
Portal 7.4.3.18 <= 7.4.3.101
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved