cbcvebase.
CVE-2023-33944
published 2023-05-24

CVE-2023-33944: Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.

Affected

6 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydigital_experience_platform7.4.0 – 7.4.3.68
liferaydxp7.3.10 – 7.3.10.u23
liferaydxp7.4.13 – 7.4.13.u68
liferayliferay_portal7.3.4 – 7.3.7
liferayportal7.3.4 – 7.4.3.68