Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.
An attacker sends the victim a crafted link containing a malicious payload embedded in the `_com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2` parameter on the role assignment page. When a logged-in user clicks on such a link, the server returns a response containing the unverified attacker's input, which is executed in the victim's browser in the context of the trusted application domain. Because this is a reflected XSS attack with Scope:Changed (S:C) marking, the script can go beyond the current page context and affect other resources.
An attacker can hijack the session of a logged-in user, steal sensitive data (including authentication tokens), or perform unauthorized actions on behalf of the victim in the Liferay application. In the worst-case scenario, complete account takeover is possible, including administrator accounts.
Liferay Portal should be updated to version 7.4.3.97 or later, and Liferay DXP to version 2023.Q3 patch 6 or later, DXP 7.4 update 93 or later, and DXP 7.3 update 34 or later. Detailed information about patches is available in the official security bulletin from the vendor at https://liferay.dev/portal/security/known-vulnerabilities.
Liferay Portal versions 7.3.3 to 7.4.3.97 and Liferay DXP 2023.Q3 before patch 6, Liferay DXP 7.4 GA to update 92, and Liferay DXP 7.3 before update 34.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HLiferay Digital Experience Platform
APPLiferay7.37.4Liferay Portal
APPLiferay7.3.3 – 7.4.3.98 (excl.)
Related vulnerabilities
RCE przez deserializację w Liferay Portal via JSONWS
Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy
RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień
Stored XSS w widżecie Document and Media platformy Liferay
Reflected XSS w ustawieniach kont Liferay Portal i DXP