Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
An attacker with an account in the system injects a malicious payload (JavaScript or HTML code) into the 'Title' field when adding or editing a document in the Document and Media widget. The malicious code is permanently saved in the platform's database (hence the 'stored' classification). Every user who views the infected document in a browser unknowingly executes the malicious script in the context of the Liferay website. The vulnerability has cross-context scope (Scope: Changed), which means it can affect resources beyond the attacker's direct environment.
An attacker can hijack sessions of other users (including administrators), gain access to sensitive data, modify portal content, or perform unauthorized actions on behalf of the victim. In case of an attack on an administrator account, complete takeover of the platform instance is possible.
Liferay Portal should be updated to a version higher than 7.4.3.101, and Liferay DXP 2023.Q3 to patch 6 or newer, and Liferay DXP 7.4 to update 93 or newer. Detailed information about available patches is available in the vendor's references at: https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47795
Liferay Portal in versions 7.4.3.18 – 7.4.3.101 and Liferay DXP 2023.Q3 before patch 6, as well as Liferay DXP 7.4 update 18 – 92.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HLiferay Digital Experience Platform
APPLiferay2023.q3.02023.q3.12023.q3.22023.q3.32023.q3.42023.q3.57.4Liferay Portal
APPLiferay7.4.3.18 – 7.4.3.102 (excl.)
Related vulnerabilities
RCE przez deserializację w Liferay Portal via JSONWS
Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy
RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień
Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról
Reflected XSS w ustawieniach kont Liferay Portal i DXP