9

CVE-2023-40191

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field

Data is provided by the National Vulnerability Database (NVD)
LiferayLiferay Portal Version >= 7.4.3.44 < 7.4.3.98
LiferayDigital Experience Platform Version7.4 Updateupdate44
LiferayDigital Experience Platform Version7.4 Updateupdate45
LiferayDigital Experience Platform Version7.4 Updateupdate46
LiferayDigital Experience Platform Version7.4 Updateupdate47
LiferayDigital Experience Platform Version7.4 Updateupdate48
LiferayDigital Experience Platform Version7.4 Updateupdate49
LiferayDigital Experience Platform Version7.4 Updateupdate50
LiferayDigital Experience Platform Version7.4 Updateupdate51
LiferayDigital Experience Platform Version7.4 Updateupdate52
LiferayDigital Experience Platform Version7.4 Updateupdate53
LiferayDigital Experience Platform Version7.4 Updateupdate54
LiferayDigital Experience Platform Version7.4 Updateupdate55
LiferayDigital Experience Platform Version7.4 Updateupdate56
LiferayDigital Experience Platform Version7.4 Updateupdate57
LiferayDigital Experience Platform Version7.4 Updateupdate58
LiferayDigital Experience Platform Version7.4 Updateupdate59
LiferayDigital Experience Platform Version7.4 Updateupdate60
LiferayDigital Experience Platform Version7.4 Updateupdate61
LiferayDigital Experience Platform Version7.4 Updateupdate62
LiferayDigital Experience Platform Version7.4 Updateupdate63
LiferayDigital Experience Platform Version7.4 Updateupdate64
LiferayDigital Experience Platform Version7.4 Updateupdate65
LiferayDigital Experience Platform Version7.4 Updateupdate66
LiferayDigital Experience Platform Version7.4 Updateupdate67
LiferayDigital Experience Platform Version7.4 Updateupdate68
LiferayDigital Experience Platform Version7.4 Updateupdate69
LiferayDigital Experience Platform Version7.4 Updateupdate70
LiferayDigital Experience Platform Version7.4 Updateupdate71
LiferayDigital Experience Platform Version7.4 Updateupdate72
LiferayDigital Experience Platform Version7.4 Updateupdate73
LiferayDigital Experience Platform Version7.4 Updateupdate74
LiferayDigital Experience Platform Version7.4 Updateupdate75
LiferayDigital Experience Platform Version7.4 Updateupdate76
LiferayDigital Experience Platform Version7.4 Updateupdate77
LiferayDigital Experience Platform Version7.4 Updateupdate78
LiferayDigital Experience Platform Version7.4 Updateupdate79
LiferayDigital Experience Platform Version7.4 Updateupdate80
LiferayDigital Experience Platform Version7.4 Updateupdate81
LiferayDigital Experience Platform Version7.4 Updateupdate82
LiferayDigital Experience Platform Version7.4 Updateupdate83
LiferayDigital Experience Platform Version7.4 Updateupdate84
LiferayDigital Experience Platform Version7.4 Updateupdate85
LiferayDigital Experience Platform Version7.4 Updateupdate86
LiferayDigital Experience Platform Version7.4 Updateupdate87
LiferayDigital Experience Platform Version7.4 Updateupdate88
LiferayDigital Experience Platform Version7.4 Updateupdate89
LiferayDigital Experience Platform Version7.4 Updateupdate90
LiferayDigital Experience Platform Version7.4 Updateupdate91
LiferayDigital Experience Platform Version7.4 Updateupdate92
LiferayDigital Experience Platform Version2023.q3.0
LiferayDigital Experience Platform Version2023.q3.1
LiferayDigital Experience Platform Version2023.q3.2
LiferayDigital Experience Platform Version2023.q3.3
LiferayDigital Experience Platform Version2023.q3.4
LiferayDigital Experience Platform Version2023.q3.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.593
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@liferay.com 9 2.3 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.