CVE-2023-33942: XSS
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's Title field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.51 - Upgrade
Upgrade
Liferay Portal/DXP Web Content Display widget (article selector)to a version that resolves this vulnerability.Fixed in 7.4.3.50 - Upgrade
Upgrade
Liferay DXP 7.4 update 50to a version that resolves this vulnerability.Fixed in 7.4 update 50
Event History
Frequently Asked Questions
What is CVE-2023-33942?
CVE-2023-33942 is a cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Portal 7.4.3.50 and Liferay DXP 7.4 update 50.
How does CVE-2023-33942 affect Liferay Portal?
CVE-2023-33942 allows remote attackers to inject arbitrary web script or HTML into a web content article's `Title` field.
What is the severity of CVE-2023-33942?
CVE-2023-33942 has a severity rating of medium with a CVSS score of 5.4.
How can the CVE-2023-33942 vulnerability be exploited?
The CVE-2023-33942 vulnerability can be exploited by injecting a crafted payload into the `Title` field of a web content article.
Is there a fix available for CVE-2023-33942?
Yes, upgrading to the latest version of Liferay Portal or Liferay DXP that includes the patch for this vulnerability will fix CVE-2023-33942.