NA

CVE-2023-40191

Published: 21/02/2024 Updated: 22/02/2024

Vulnerability Summary

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 up to and including 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field