Vulnerabilities > Liferay > Digital Experience Platform > 2023.q3.0

DATE CVE VULNERABILITY TITLE RISK
2024-02-21 CVE-2023-47795 Cross-site Scripting vulnerability in Liferay Portal
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
network
low complexity
liferay CWE-79
5.4
2024-02-21 CVE-2023-40191 Cross-site Scripting vulnerability in Liferay Portal
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
network
low complexity
liferay CWE-79
6.1
2024-02-21 CVE-2023-42498 Cross-site Scripting vulnerability in Liferay Portal
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
network
low complexity
liferay CWE-79
6.1
2024-02-20 CVE-2024-26270 Unspecified vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
network
high complexity
liferay
5.3
2024-02-20 CVE-2023-44308 Open Redirect vulnerability in Liferay Digital Experience Platform
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
network
low complexity
liferay CWE-601
6.1
2024-02-20 CVE-2023-5190 Open Redirect vulnerability in Liferay Digital Experience Platform 2023.Q3.0/2023.Q3.1/7.4
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.
network
low complexity
liferay CWE-601
6.1