CVE-2023-47797: XSS
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the plbackurltitle parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-47797.
What is the severity of CVE-2023-47797?
The severity of CVE-2023-47797 is critical with a CVSS score of 9.6.
How does CVE-2023-47797 impact Liferay Portal?
CVE-2023-47797 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95.
How can I fix CVE-2023-47797?
To fix CVE-2023-47797, upgrade to Liferay Portal version 7.4.3.96 or later.
Where can I find more information about CVE-2023-47797?
You can find more information about CVE-2023-47797 on the Liferay Portal Security Advisories page, the NIST National Vulnerability Database, and the GitHub Security Advisory page.