QID 730997
Date Published: 2023-12-06
QID 730997: Liferay Portal Multiple stored Cross-Site Scripting (XSS) Vulnerability
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal and Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
Affected Versions:
Liferay Portal 7.4.2 - 7.4.3.53
QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal and Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
CVEs related to QID 730997
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-44309 |
|