CVE-2024-11993Cross-site Scripting in Digital Experience Platform

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 74.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17

Description

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.1.07.4.3.39
CVEListV5liferay/portal7.4.07.4.3.38
CVEListV5liferay/dxp7.4.137.4.13-u38

🔴Vulnerability Details

3
CVEList
CVE-2024-11993: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 72024-12-17
OSV
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting2024-12-17
GHSA
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting2024-12-17
CVE-2024-11993 — Cross-site Scripting | cvebase