5.4
CVSSv3

CVE-2023-44310

Published: 17/10/2023 Updated: 24/10/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 up to and including 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.

Vulnerable Product Search on Vulmon Subscribe to Product

liferay digital experience platform 7.1

liferay digital experience platform 7.4

liferay liferay portal