5.4

CVE-2023-33943

Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job Title text field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.4 Updateupdate21
LiferayDigital Experience Platform Version7.4 Updateupdate22
LiferayDigital Experience Platform Version7.4 Updateupdate23
LiferayDigital Experience Platform Version7.4 Updateupdate24
LiferayDigital Experience Platform Version7.4 Updateupdate25
LiferayDigital Experience Platform Version7.4 Updateupdate26
LiferayDigital Experience Platform Version7.4 Updateupdate27
LiferayDigital Experience Platform Version7.4 Updateupdate28
LiferayDigital Experience Platform Version7.4 Updateupdate29
LiferayDigital Experience Platform Version7.4 Updateupdate30
LiferayDigital Experience Platform Version7.4 Updateupdate31
LiferayDigital Experience Platform Version7.4 Updateupdate32
LiferayDigital Experience Platform Version7.4 Updateupdate33
LiferayDigital Experience Platform Version7.4 Updateupdate34
LiferayDigital Experience Platform Version7.4 Updateupdate35
LiferayDigital Experience Platform Version7.4 Updateupdate36
LiferayDigital Experience Platform Version7.4 Updateupdate37
LiferayDigital Experience Platform Version7.4 Updateupdate38
LiferayDigital Experience Platform Version7.4 Updateupdate39
LiferayDigital Experience Platform Version7.4 Updateupdate40
LiferayDigital Experience Platform Version7.4 Updateupdate41
LiferayDigital Experience Platform Version7.4 Updateupdate42
LiferayDigital Experience Platform Version7.4 Updateupdate43
LiferayDigital Experience Platform Version7.4 Updateupdate44
LiferayDigital Experience Platform Version7.4 Updateupdate45
LiferayDigital Experience Platform Version7.4 Updateupdate46
LiferayDigital Experience Platform Version7.4 Updateupdate47
LiferayDigital Experience Platform Version7.4 Updateupdate48
LiferayDigital Experience Platform Version7.4 Updateupdate49
LiferayDigital Experience Platform Version7.4 Updateupdate50
LiferayDigital Experience Platform Version7.4 Updateupdate51
LiferayDigital Experience Platform Version7.4 Updateupdate52
LiferayDigital Experience Platform Version7.4 Updateupdate53
LiferayDigital Experience Platform Version7.4 Updateupdate54
LiferayDigital Experience Platform Version7.4 Updateupdate55
LiferayDigital Experience Platform Version7.4 Updateupdate56
LiferayDigital Experience Platform Version7.4 Updateupdate57
LiferayDigital Experience Platform Version7.4 Updateupdate58
LiferayDigital Experience Platform Version7.4 Updateupdate59
LiferayDigital Experience Platform Version7.4 Updateupdate60
LiferayDigital Experience Platform Version7.4 Updateupdate61
LiferayDigital Experience Platform Version7.4 Updateupdate62
LiferayLiferay Portal Version >= 7.4.3.21 <= 7.4.3.62
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.