CVE-2023-33944: XSS
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's URL text field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.69 - Upgrade
Upgrade
Liferay Portal Layout moduleto a version that resolves this vulnerability.Fixed in 7.3.4 through 7.4.3.68 - Upgrade
Upgrade
Liferay DXP Layout moduleto a version that resolves this vulnerability.Fixed in 7.3 before update 24 - Upgrade
Upgrade
Liferay DXP Layout moduleto a version that resolves this vulnerability.Fixed in 7.4 before update 69 - Configuration
In container type layout fragments, treat the `URL` text field as untrusted: apply input validation and output encoding/sanitization to prevent crafted payloads from injecting arbitrary web script or HTML.
Layout module (container type layout fragment) URL text field = Sanitize/validate input (prevent injection of arbitrary web script/HTML)
Event History
Frequently Asked Questions
What is CVE-2023-33944?
CVE-2023-33944 is a cross-site scripting (XSS) vulnerability in the Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69.
What is the severity of CVE-2023-33944?
The severity of CVE-2023-33944 is medium, with a severity value of 6.1.
How does CVE-2023-33944 affect Liferay Portal?
CVE-2023-33944 allows remote attackers to inject arbitrary web script or HTML into a container type layout fragment's URL, leading to potential cross-site scripting attacks.
Which versions of Liferay Portal are affected by CVE-2023-33944?
CVE-2023-33944 affects Liferay Portal versions 7.3.4 through 7.4.3.68.
How can I fix CVE-2023-33944?
To fix CVE-2023-33944, it is recommended to update Liferay Portal to version 7.4.3.69 or the latest available patch.