Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
28 Jan 2025, 21:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47795 - Vendor Advisory | |
CPE | cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.3:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.1:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.0:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.4:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.2:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023.q3.5:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:* |
|
First Time |
Liferay digital Experience Platform
Liferay liferay Portal Liferay |
21 Nov 2024, 08:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47795 - |
22 Feb 2024, 19:07
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Feb 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-21 14:15
Updated : 2025-01-28 21:17
NVD link : CVE-2023-47795
Mitre link : CVE-2023-47795
CVE.ORG link : CVE-2023-47795
JSON object : View
Products Affected
liferay
- liferay_portal
- digital_experience_platform
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')