QID 731005
Date Published: 2023-12-11
QID 731005: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page Content text field.
Affected Versions:
Liferay Portal 7.1.0 - 7.4.3.87
QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page Content text field.
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
CVEs related to QID 731005
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-42628 |
|