Stored XSS vulnerability in Liferay Portal
CVE-2023-47795

5.4MEDIUM

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
21 February 2024

What is CVE-2023-47795?

The vulnerability in Liferay Portal and DXP allows for a stored cross-site scripting (XSS) attack through the Document and Media widget. This flaw permits remote authenticated users to inject malicious web scripts or HTML content via a specially crafted payload inserted into a document's 'Title' text field. The affected versions include Liferay Portal 7.4.3.18 up to 7.4.3.101 and Liferay DXP 2023.Q3 before patch 6, exposing systems to potential breaches and unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DXP 2023.q3.1 <= 2023.q3.5

DXP 7.4.13.u18 <= 7.4.13.u92

Portal 7.4.3.18 <= 7.4.3.101

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erwin Krazek
.