CRITICAL🇵🇱 Wersja polska

CVE-2023-40191

CVSS 9.0v3.1pub. 2024-02-21upd. 2025-01-28

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    2023.q3.02023.q3.12023.q3.22023.q3.32023.q3.42023.q3.57.4
  • Liferay Portal

    APP
    Liferay
    7.4.3.44 – 7.4.3.98 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-8980CRITICAL9.6PL ✓same product

Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy

CVE-2024-38002CRITICAL9.0PL ✓same product

RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień

CVE-2023-47795CRITICAL9.0PL ✓same product

Stored XSS w widżecie Document and Media platformy Liferay

CVE-2023-42496CRITICAL9.6PL ✓same product

Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról