logo

CVE-2023-33939 com.liferay.portal:release.portal.bom

Package

Manager: maven
Name: com.liferay.portal:release.portal.bom
Vulnerable Version: >=7.1.0 <7.4.3.13

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

EPSS: 0.00142 pctl0.34934

Details

Cross-site scripting in Liferay Portal Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a facet label.

Metadata

Created: 2023-05-24T15:30:27Z
Modified: 2023-05-24T18:04:23Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-53mw-69qx-q4fc/GHSA-53mw-69qx-q4fc.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-53mw-69qx-q4fc
Finding: F425
Auto approve: 1