Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
An attacker sends the victim a specially crafted link containing a malicious payload in the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key` parameter. When a logged-in user clicks this link, the server reflects the unvalidated parameter back to the browser, where it is executed as script code. The attack vector is network-based, does not require authentication on the attacker's side, but requires user interaction (UI:R), which is typical for reflected XSS. The changed scope (S:C) indicates that the effects may extend beyond the context of the application itself.
An attacker can hijack the session of a logged-in user, steal credentials or sensitive information, and perform actions on behalf of the victim in the context of the Liferay application. In the case of portal administrators, the consequences may include complete takeover of the platform.
Liferay DXP 2023.Q3 should be updated to patch 5 or newer, and Liferay DXP 7.4 to update 93 or newer. For Liferay Portal, patches available from the vendor should be applied according to references at https://liferay.dev/portal/security/known-vulnerabilities. Until the patch is deployed, it is recommended to restrict access to the Language Override screen only to trusted users.
Liferay Portal versions 7.4.3.8 to 7.4.3.97; Liferay DXP 2023.Q3 before patch 5; Liferay DXP 7.4 update 4 to update 92
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HLiferay Digital Experience Platform
APPLiferay2023.q3.02023.q3.12023.q3.22023.q3.32023.q3.47.4Liferay Portal
APPLiferay7.4.3.8 – 7.4.3.98 (excl.)
Related vulnerabilities
RCE przez deserializację w Liferay Portal via JSONWS
Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy
RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień
Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról
Reflected XSS w ustawieniach kont Liferay Portal i DXP