CVE-2023-42629
Summary
| CVE | CVE-2023-42629 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-17 09:15:00 UTC |
| Updated | 2023-11-10 03:15:00 UTC |
| Description | Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Liferay | Digital Experience Platform | 7.4 | - | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update1 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update21 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update34 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update36 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update41 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update48 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update50 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update52 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update62 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update67 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update76 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update81 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update82 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update83 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update84 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update85 | All | All |
| Application | Liferay | Digital Experience Platform | 7.4 | update86 | All | All |
| Application | Liferay | Liferay Portal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Persistent cross-site scripting vulnerabilities in Liferay Portal | Pentagrid AG | www.pentagrid.ch | ||
| CVE-2023-42629 Stored XSS vulnerability with vocabulary description - Liferay | MISC | liferay.dev | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730998 Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability