CVE-2023-42629: XSS
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42629?
CVE-2023-42629 is a stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88.
How does CVE-2023-42629 affect Liferay Portal?
CVE-2023-42629 allows remote attackers to inject arbitrary web script or HTML into a Vocabulary's 'description' text field.
What is the severity of CVE-2023-42629?
CVE-2023-42629 has a severity rating of critical.
Which versions of Liferay Portal are affected by CVE-2023-42629?
CVE-2023-42629 affects Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88.
Is there a fix available for CVE-2023-42629?
Yes, a fix is available for CVE-2023-42629. Update Liferay Portal to version 7.4.3.88 or apply the recommended security patch.