logo

CVE-2023-44309 com.liferay.portal:release.dxp.bom

Package

Manager: maven
Name: com.liferay.portal:release.dxp.bom
Vulnerable Version: >=7.4.0 <7.4.13.u54

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00152 pctl0.36517

Details

Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components before 3.0.25 from Liferay Portal (7.4.2 through 7.4.3.53), and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.

Metadata

Created: 2023-10-17T09:30:23Z
Modified: 2025-08-08T21:14:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-j663-6jpj-xx8c
Finding: F425
Auto approve: 1