CRITICAL🇵🇱 Wersja polska

CVE-2023-42496

CVSS 9.6v3.1pub. 2024-02-21upd. 2025-01-28

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.

🤖 AI Analysis
How it works

An attacker sends the victim a crafted link containing a malicious payload embedded in the `_com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2` parameter on the role assignment page. When a logged-in user clicks on such a link, the server returns a response containing the unverified attacker's input, which is executed in the victim's browser in the context of the trusted application domain. Because this is a reflected XSS attack with Scope:Changed (S:C) marking, the script can go beyond the current page context and affect other resources.

Impact

An attacker can hijack the session of a logged-in user, steal sensitive data (including authentication tokens), or perform unauthorized actions on behalf of the victim in the Liferay application. In the worst-case scenario, complete account takeover is possible, including administrator accounts.

Mitigation & patch

Liferay Portal should be updated to version 7.4.3.97 or later, and Liferay DXP to version 2023.Q3 patch 6 or later, DXP 7.4 update 93 or later, and DXP 7.3 update 34 or later. Detailed information about patches is available in the official security bulletin from the vendor at https://liferay.dev/portal/security/known-vulnerabilities.

Who is affected

Liferay Portal versions 7.3.3 to 7.4.3.97 and Liferay DXP 2023.Q3 before patch 6, Liferay DXP 7.4 GA to update 92, and Liferay DXP 7.3 before update 34.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    7.37.4
  • Liferay Portal

    APP
    Liferay
    7.3.3 – 7.4.3.98 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-8980CRITICAL9.6PL ✓same product

Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy

CVE-2024-38002CRITICAL9.0PL ✓same product

RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień

CVE-2023-47795CRITICAL9.0PL ✓same product

Stored XSS w widżecie Document and Media platformy Liferay

CVE-2023-40191CRITICAL9.0PL ✓same product

Reflected XSS w ustawieniach kont Liferay Portal i DXP