Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33942


Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.


Published

2023-05-24T15:15:09.807

Last Modified

2024-11-21T08:06:15.487

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application liferay digital_experience_platform 7.4 Yes
Application liferay liferay_portal 7.4.3.50 Yes

References