6.1

CVE-2023-33944

Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version >= 7.4.0 <= 7.4.3.68
LiferayDigital Experience Platform Version7.3 Updateupdate1
LiferayDigital Experience Platform Version7.3 Updateupdate10
LiferayDigital Experience Platform Version7.3 Updateupdate11
LiferayDigital Experience Platform Version7.3 Updateupdate12
LiferayDigital Experience Platform Version7.3 Updateupdate13
LiferayDigital Experience Platform Version7.3 Updateupdate14
LiferayDigital Experience Platform Version7.3 Updateupdate15
LiferayDigital Experience Platform Version7.3 Updateupdate16
LiferayDigital Experience Platform Version7.3 Updateupdate17
LiferayDigital Experience Platform Version7.3 Updateupdate18
LiferayDigital Experience Platform Version7.3 Updateupdate19
LiferayDigital Experience Platform Version7.3 Updateupdate2
LiferayDigital Experience Platform Version7.3 Updateupdate20
LiferayDigital Experience Platform Version7.3 Updateupdate21
LiferayDigital Experience Platform Version7.3 Updateupdate22
LiferayDigital Experience Platform Version7.3 Updateupdate23
LiferayDigital Experience Platform Version7.3 Updateupdate24
LiferayDigital Experience Platform Version7.3 Updateupdate3
LiferayDigital Experience Platform Version7.3 Updateupdate4
LiferayDigital Experience Platform Version7.3 Updateupdate5
LiferayDigital Experience Platform Version7.3 Updateupdate6
LiferayDigital Experience Platform Version7.3 Updateupdate7
LiferayDigital Experience Platform Version7.3 Updateupdate8
LiferayDigital Experience Platform Version7.3 Updateupdate9
LiferayLiferay Portal Version >= 7.3.4 <= 7.3.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.