Description
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48666 | Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree Menu |
Github GHSA |
GHSA-j5gv-w838-mmcx | Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree Menu |
References
History
No history.
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2024-09-13T16:31:11.575Z
Reserved: 2023-09-28T11:23:54.829Z
Link: CVE-2023-44310
Updated: 2024-08-02T19:59:51.964Z
Status : Modified
Published: 2023-10-17T10:15:09.793
Modified: 2024-11-21T08:25:38.483
Link: CVE-2023-44310
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA