9.6
CVE-2023-42498
- EPSS 0.38%
- Published 21.02.2024 03:15:08
- Last modified 28.01.2025 02:47:39
- Source security@liferay.com
- Teams watchlist Login
- Open Login
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
Data is provided by the National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal Version >= 7.4.3.8 < 7.4.3.98
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate16
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate17
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate18
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate19
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate20
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate21
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate22
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate23
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate24
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate25
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate26
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate27
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate28
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate29
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate30
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate31
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate32
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate33
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate34
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate35
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate36
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate37
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate38
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate39
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate40
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate41
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate42
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate43
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate44
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate45
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate46
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate47
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate48
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate49
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate50
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate51
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate52
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate53
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate54
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate55
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate56
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate57
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate58
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate59
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate60
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate61
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate62
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate63
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate64
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate65
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate66
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate67
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate68
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate69
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate70
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate71
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate72
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate73
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate74
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate75
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate76
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate77
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate78
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate79
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate80
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate81
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate82
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate83
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate84
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate85
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate86
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate87
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate88
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate89
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate9
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate90
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate91
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate92
Liferay ≫ Digital Experience Platform Version2023.q3.0
Liferay ≫ Digital Experience Platform Version2023.q3.1
Liferay ≫ Digital Experience Platform Version2023.q3.2
Liferay ≫ Digital Experience Platform Version2023.q3.3
Liferay ≫ Digital Experience Platform Version2023.q3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.38% | 0.584 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
security@liferay.com | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.