Headline
CVE-2023-33941: CVE-2023-33941 Reflected XSS with 'code' and 'error' in OAuth2ProviderApplicationRedirect - Liferay
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module’s OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
This website uses cookies to ensure you get the best experience. Learn More.
Accept
- Ask
- Blogs
- Download
- Feedback
- Help
- Learn
- Projects
- /dev/24
- Log In
Known Vulnerabilities
- Overview
- Reporting Security Issues
- Known Vulnerabilities
- Hall of Fame
Releases
Liferay Portal 7.4
Liferay Portal 7.3
Liferay Portal 7.2
Liferay Portal 7.1
Liferay Portal 7.0
Liferay Portal 6.2 CE
Liferay Faces
Liferay DXP 7.4
Liferay DXP 7.3
Liferay DXP 7.2
LIferay DXP 7.1
LIferay DXP 7.0
CVE-2023-33941 Reflected XSS with ‘code’ and ‘error’ in OAuth2ProviderApplicationRedirect
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module’s OAuth2ProviderApplicationRedirect class in Liferay Portal and Liferay DXP allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
Severity
6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Affected Version(s)
- Liferay DXP 7.4 update 41 through 52
- Liferay Portal 7.4.3.41 - 7.4.3.52
Fixed Version(s)
- Liferay DXP 7.4 update 53
- Liferay Portal 7.4.3.53
Publication date: Wed, 24 May 2023 07:00:00 +0000
Security advisories for Liferay’s enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.
Related news
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.