QID 730998
Date Published: 2023-12-06
QID 730998: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary has description text field.
Affected Versions:
Liferay Portal 7.4.2 - 7.4.3.87
QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary has description text field.
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
CVEs related to QID 730998
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-42629 |
|