CVE-2023-44311: XSS
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class before 4.0.51 from Liferay Portal (7.4.3.41 through 7.4.3.89), and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.
Other sources
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44311?
The severity of CVE-2023-44311 is critical with a CVSS score of 9.6.
What is the affected software of CVE-2023-44311?
The affected software of CVE-2023-44311 is Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89.
How can remote attackers exploit CVE-2023-44311?
Remote attackers can exploit CVE-2023-44311 by injecting arbitrary web script or HTML via the OAuth2ProviderApplicationRedirect class.
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-44311?
The Common Weakness Enumeration (CWE) ID of CVE-2023-44311 is CWE-79.
Where can I find more information about CVE-2023-44311?
You can find more information about CVE-2023-44311 on the following website: [CVE-2023-44311](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-44311).