CVE-2023-42627

Description

Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Address, (4) Shipping Address 2, (5) Shipping Address 3, (6) Shipping Zip, (7) Shipping City, (8) Shipping Region (9), Shipping Country, (10) Billing Name, (11) Billing Phone Number, (12) Billing Address, (13) Billing Address 2, (14) Billing Address 3, (15) Billing Zip, (16) Billing City, (17) Billing Region, (18) Billing Country, or (19) Region Code.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.208

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-42627 are affected in Liferay - release.dxp.bom 7.3.10Windows
Vulnerabilities CVE-2023-42627 are fixed in Liferay - com.liferay.commerce.address.content.web 4.0.35Windows
Vulnerabilities CVE-2023-42627 are affected in Liferay - release.dxp.bom for Linux 7.3.10Linux
Vulnerabilities CVE-2023-42627 are fixed in Liferay - com.liferay.commerce.address.content.web for Linux 4.0.35Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234