CVE-2023-44310: XSS
Stored cross-site scripting (XSS) vulnerability in Page Tree menu in Liferay Layout Implementation before 6.0.102 from Liferay Portal (7.3.6 through 7.4.3.78), and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Other sources
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44310?
The severity of CVE-2023-44310 is critical with a severity value of 9.
How does the vulnerability CVE-2023-44310 affect Liferay Portal and Liferay DXP?
The vulnerability affects Liferay Portal versions 7.3.6 through 7.4.3.78 and Liferay DXP versions 7.3 fix pack 1 through update 23, and 7.4 before update 79.
What is the CWE of CVE-2023-44310?
The CWE of CVE-2023-44310 is 79.
How can remote attackers exploit the vulnerability CVE-2023-44310?
Remote attackers can exploit the vulnerability by injecting a crafted payload into a page's "Name" text field, allowing them to inject arbitrary web script or HTML.
Is there a fix available for CVE-2023-44310?
Yes, a fix is available for CVE-2023-44310. Please refer to the official reference for more details.