CRITICAL🇵🇱 Wersja polska

CVE-2023-42498

CVSS 9.6v3.1pub. 2024-02-21upd. 2025-01-28

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.

🤖 AI Analysis
How it works

An attacker sends the victim a specially crafted link containing a malicious payload in the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key` parameter. When a logged-in user clicks this link, the server reflects the unvalidated parameter back to the browser, where it is executed as script code. The attack vector is network-based, does not require authentication on the attacker's side, but requires user interaction (UI:R), which is typical for reflected XSS. The changed scope (S:C) indicates that the effects may extend beyond the context of the application itself.

Impact

An attacker can hijack the session of a logged-in user, steal credentials or sensitive information, and perform actions on behalf of the victim in the context of the Liferay application. In the case of portal administrators, the consequences may include complete takeover of the platform.

Mitigation & patch

Liferay DXP 2023.Q3 should be updated to patch 5 or newer, and Liferay DXP 7.4 to update 93 or newer. For Liferay Portal, patches available from the vendor should be applied according to references at https://liferay.dev/portal/security/known-vulnerabilities. Until the patch is deployed, it is recommended to restrict access to the Language Override screen only to trusted users.

Who is affected

Liferay Portal versions 7.4.3.8 to 7.4.3.97; Liferay DXP 2023.Q3 before patch 5; Liferay DXP 7.4 update 4 to update 92

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    2023.q3.02023.q3.12023.q3.22023.q3.32023.q3.47.4
  • Liferay Portal

    APP
    Liferay
    7.4.3.8 – 7.4.3.98 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-8980CRITICAL9.6PL ✓same product

Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy

CVE-2024-38002CRITICAL9.0PL ✓same product

RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień

CVE-2023-42496CRITICAL9.6PL ✓same product

Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról

CVE-2023-40191CRITICAL9.0PL ✓same product

Reflected XSS w ustawieniach kont Liferay Portal i DXP