CVE-2023-42497 — Cross-site Scripting in Portal
Severity
6.1MEDIUMNVD
CNA9.6
EPSS
0.2%
top 58.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Description
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages4 packages
🔴Vulnerability Details
3CVEList▶
CVE-2023-42497: Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7↗2023-10-17
GHSA▶
Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page↗2023-10-17
OSV▶
Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page↗2023-10-17