CVE-2024-11993: XSS
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
Other sources
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11993?
CVE-2024-11993 is classified as a reflected cross-site scripting (XSS) vulnerability, which can have a high severity depending on its potential impact on users.
How do I fix CVE-2024-11993?
To remediate CVE-2024-11993, update your Liferay Portal to version 7.4.3.39 or Liferay DXP to version 7.4.13.u39.
Which versions are affected by CVE-2024-11993?
CVE-2024-11993 affects Liferay Portal versions 7.1.0 to 7.4.3.38 and Liferay DXP versions 7.3 GA through update 36.
What types of attacks can CVE-2024-11993 facilitate?
CVE-2024-11993 can facilitate remote attackers executing arbitrary web scripts or HTML, potentially compromising user interactions.
Is there a workaround for CVE-2024-11993?
There are no specific workarounds for CVE-2024-11993; applying the necessary updates is the recommended solution.