QID 731022
Date Published: 2023-12-26
QID 731022: Liferay Portal Stored Cross-Site Scripting (XSS) Vulnerability
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form has name field.
Affected Versions:
Liferay Portal 7.1.0 - 7.1.3
Liferay Portal 7.2.0 - 7.2.1
Liferay Portal 7.3.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form has name field.
Solution
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731022
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33937 |
|