CVE-2023-44309

Description

Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.199

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-44309 are fixed in Liferay - release.dxp.bom 7.4.13Windows
Vulnerabilities CVE-2023-44309 are fixed in Liferay - com.liferay.fragment.entry.processor.impl 3.0.25Windows
Vulnerabilities CVE-2023-44309 are fixed in Liferay - release.dxp.bom for Linux 7.4.13Linux
Vulnerabilities CVE-2023-44309 are fixed in Liferay - com.liferay.fragment.entry.processor.impl for Linux 3.0.25Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234