CVE-2023-33940: XSS
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.31 - Upgrade
Upgrade
Liferay Portal / Liferay DXP 7.4to a version that resolves this vulnerability.Fixed in 7.4.3.31
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-33940.
What is the severity of CVE-2023-33940?
The severity of CVE-2023-33940 is medium with a CVSS score of 5.4.
How does the vulnerability in CVE-2023-33940 work?
The vulnerability in CVE-2023-33940 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
Which software versions are affected by CVE-2023-33940?
The affected software versions are Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31.
How can I fix the vulnerability in CVE-2023-33940?
To fix the vulnerability in CVE-2023-33940, update to the latest version of Liferay Portal or Liferay DXP.