QID 731017
Date Published: 2023-12-26
QID 731017: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability
Cross-site scripting (XSS) vulnerability in the Web Content Display widget has article selector in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article has Title field.
Affected Versions:
Liferay Portal 7.4.3.50
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article has Title field.
Solution
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731017
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33942 |
|