Headline
CVE-2023-33937: CVE-2023-33937 Stored XSS with form name in form configuration - Liferay
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form’s name
field.
This website uses cookies to ensure you get the best experience. Learn More.
Accept
- Ask
- Blogs
- Download
- Feedback
- Help
- Learn
- Projects
- /dev/24
- Log In
Known Vulnerabilities
- Overview
- Reporting Security Issues
- Known Vulnerabilities
- Hall of Fame
Releases
Liferay Portal 7.4
Liferay Portal 7.3
Liferay Portal 7.2
Liferay Portal 7.1
Liferay Portal 7.0
Liferay Portal 6.2 CE
Liferay Faces
Liferay DXP 7.4
Liferay DXP 7.3
Liferay DXP 7.2
LIferay DXP 7.1
LIferay DXP 7.0
CVE-2023-33937 Stored XSS with form name in form configuration
Description
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal, and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form’s `name` field.
Severity
5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Affected Version(s)
- Liferay DXP 7.1 before fix pack 18
- Liferay DXP 7.2 before fix pack 5
- Liferay Portal 7.1.0 - 7.1.3
- Liferay Portal 7.2.0 - 7.2.1
- Liferay Portal 7.3.0
Fixed Version(s)
- Liferay DXP 7.1 fix pack 18
- Liferay DXP 7.2 fix pack 5
- Liferay Portal 7.3.1
Publication date: Wed, 24 May 2023 07:00:00 +0000
Security advisories for Liferay’s enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.
Related news
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.