QID 731021
Date Published: 2023-12-26
QID 731021: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability
Cross-site scripting (XSS) vulnerability in the App Builder module has custom object details page in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object has Name field.
Affected Versions:
Liferay Portal 7.3.0 - 7.3.7
Liferay Portal 7.4.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object has Name field.
Solution
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731021
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33938 |
|