CVE-2023-33943: XSS
Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job Title text field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.63 - Upgrade
Upgrade
Liferay Portal / Liferay DXP Account moduleto a version that resolves this vulnerability.Fixed in 7.4.3.62 - Upgrade
Upgrade
Liferay DXP 7.4 updateto a version that resolves this vulnerability.Fixed in 7.4 update 21 through 62
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33943?
The severity of CVE-2023-33943 is medium with a CVSS score of 5.4.
How does CVE-2023-33943 impact Liferay Portal?
CVE-2023-33943 allows remote attackers to inject arbitrary web script or HTML into a user's First Name, Middle Name, or Last Name fields in Liferay Portal, potentially impacting the security and integrity of the affected user's account.
Which versions of Liferay Portal are affected by CVE-2023-33943?
Liferay Portal versions 7.4.3.21 through 7.4.3.62 are affected by CVE-2023-33943.
How can I fix CVE-2023-33943?
To fix CVE-2023-33943, it is recommended to update Liferay Portal to a version that includes the security patch which addresses this vulnerability.
Where can I find more information about CVE-2023-33943?
You can find more information about CVE-2023-33943 at the following URL: https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33943