CVE-2023-42497: XSS
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the comliferaytranslationwebinternalportletTranslationPortletredirect parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42497?
The severity of CVE-2023-42497 is critical.
What is the affected software for CVE-2023-42497?
The affected software for CVE-2023-42497 is Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86.
How does CVE-2023-42497 affect Liferay Digital Experience Platform?
CVE-2023-42497 affects Liferay Digital Experience Platform 7.4 and its update versions.
What is the common weakness enumeration (CWE) of CVE-2023-42497?
The common weakness enumeration (CWE) of CVE-2023-42497 is CWE-79.
Where can I find more information about CVE-2023-42497?
You can find more information about CVE-2023-42497 at this link: [https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42497](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42497)