Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Liferay

Published: 2023-10-17T08:23:27.403Z

Updated: 2023-10-17T08:23:27.403Z

Reserved: 2023-09-28T11:23:54.829Z


Link: CVE-2023-44309

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-17T09:15:10.347

Modified: 2023-10-24T17:15:31.203


Link: CVE-2023-44309

JSON object: View

cve-icon Redhat Information

No data.

CWE