Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown
CVE-2023-42628
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's ‘Content’ text field.
0
Attacker Value
Unknown
CVE-2023-44311
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.
0
Attacker Value
Unknown
CVE-2023-44310
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
0
Attacker Value
Unknown
CVE-2023-44309
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
0
Attacker Value
Unknown
CVE-2023-42629
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
0
Attacker Value
Unknown
CVE-2023-42497
Disclosure Date: October 17, 2023 (last updated October 24, 2023)
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
0
Attacker Value
Unknown
CVE-2023-3426
Disclosure Date: August 02, 2023 (last updated October 08, 2023)
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
0
Attacker Value
Unknown
CVE-2023-33950
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
0
Attacker Value
Unknown
CVE-2023-33948
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
0
Attacker Value
Unknown
CVE-2023-33947
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.
0