CVE-2023-44309: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44309?
CVE-2023-44309 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML via a crafted payload in Liferay Portal and Liferay DXP versions 7.4.2 through 7.4.3.53.
How severe is CVE-2023-44309?
CVE-2023-44309 has a severity rating of critical.
Which software versions are affected by CVE-2023-44309?
Liferay Portal versions 7.4.2 through 7.4.3.53, and Liferay DXP versions 7.4 before update 54 are affected by CVE-2023-44309.
What is the Common Weakness Enumeration (CWE) number for CVE-2023-44309?
The CWE number for CVE-2023-44309 is 79.
Where can I find more information about CVE-2023-44309?
You can find more information about CVE-2023-44309 at the following link: https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-44309