CRITICAL🇵🇱 Wersja polska

CVE-2023-47795

CVSS 9.0v3.1pub. 2024-02-21upd. 2025-01-28

Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.

🤖 AI Analysis
How it works

An attacker with an account in the system injects a malicious payload (JavaScript or HTML code) into the 'Title' field when adding or editing a document in the Document and Media widget. The malicious code is permanently saved in the platform's database (hence the 'stored' classification). Every user who views the infected document in a browser unknowingly executes the malicious script in the context of the Liferay website. The vulnerability has cross-context scope (Scope: Changed), which means it can affect resources beyond the attacker's direct environment.

Impact

An attacker can hijack sessions of other users (including administrators), gain access to sensitive data, modify portal content, or perform unauthorized actions on behalf of the victim. In case of an attack on an administrator account, complete takeover of the platform instance is possible.

Mitigation & patch

Liferay Portal should be updated to a version higher than 7.4.3.101, and Liferay DXP 2023.Q3 to patch 6 or newer, and Liferay DXP 7.4 to update 93 or newer. Detailed information about available patches is available in the vendor's references at: https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47795

Who is affected

Liferay Portal in versions 7.4.3.18 – 7.4.3.101 and Liferay DXP 2023.Q3 before patch 6, as well as Liferay DXP 7.4 update 18 – 92.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    2023.q3.02023.q3.12023.q3.22023.q3.32023.q3.42023.q3.57.4
  • Liferay Portal

    APP
    Liferay
    7.4.3.18 – 7.4.3.102 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-8980CRITICAL9.6PL ✓same product

Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy

CVE-2024-38002CRITICAL9.0PL ✓same product

RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień

CVE-2023-42496CRITICAL9.6PL ✓same product

Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról

CVE-2023-40191CRITICAL9.0PL ✓same product

Reflected XSS w ustawieniach kont Liferay Portal i DXP