CVE-2023-33938: XSS
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's Name field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.1
Event History
Frequently Asked Questions
What is CVE-2023-33938?
CVE-2023-33938 is a Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14.
How does CVE-2023-33938 impact the affected software?
CVE-2023-33938 allows remote attackers to inject arbitrary web script or HTML into an App Builder custom object.
What is the severity of CVE-2023-33938?
CVE-2023-33938 has a severity rating of 6.1, which is considered medium.
Which software versions are affected by CVE-2023-33938?
CVE-2023-33938 affects Liferay Portal versions 7.3.0 through 7.4.0 and Liferay DXP 7.3 before update 14.
How can I fix CVE-2023-33938?
To fix CVE-2023-33938, update Liferay Portal to version 7.4.0 or later, or Liferay DXP to update 14 or later.