Vulnerabilities > Liferay > Digital Experience Platform > 2023.q3.5

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-26271 Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter.
network
low complexity
liferay CWE-352
8.8
2024-10-22 CVE-2024-26272 Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the p_l_back_url parameter.
network
low complexity
liferay CWE-352
8.8
2024-10-22 CVE-2024-26273 Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_commerce_catalog_web_internal_portlet_CommerceCatalogsPortlet_redirect parameter.
network
low complexity
liferay CWE-352
8.8
2024-10-22 CVE-2024-38002 Incorrect Authorization vulnerability in Liferay Digital Experience Platform and Liferay Portal
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
network
low complexity
liferay CWE-863
8.8
2024-02-21 CVE-2023-47795 Cross-site Scripting vulnerability in Liferay Portal
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
network
low complexity
liferay CWE-79
5.4
2024-02-21 CVE-2023-40191 Cross-site Scripting vulnerability in Liferay Portal
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
network
low complexity
liferay CWE-79
6.1
2024-02-20 CVE-2023-44308 Open Redirect vulnerability in Liferay Digital Experience Platform
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
network
low complexity
liferay CWE-601
6.1
2024-02-20 CVE-2023-5190 Open Redirect vulnerability in Liferay Digital Experience Platform 2023.Q3.0/2023.Q3.1/7.4
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.
network
low complexity
liferay CWE-601
6.1