CVE-2023-44309
Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components
9.0
CRITICAL
CVSS 3.1
EPSS 0.46%
Description
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
How to fix CVE-2023-44309
To remediate CVE-2023-44309, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 7.4.13.u54 or later
- —upgrade to 3.0.25 or later
Is CVE-2023-44309 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 7.4.0, <= 7.4.0 | >= 7.4-update1.0, <= 7.4-update1.0, >= 7.4-update21.0, <= 7.4-update21.0, >= 7.4-update34.0, <= 7.4-update34.0, >= 7.4-update36.0, <= 7.4-update36.0, >= 7.4-update41.0, <= 7.4-update41.0, >= 7.4-update48.0, <= 7.4-update48.0, >= 7.4-update50.0, <= 7.4-update50.0, >= 7.4-update52.0, <= 7.4-update52.0
- >= 7.4.0, < 7.4.13.u54
- from 0, < 3.0.25
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |