CVE-2023-3193
Liferay Portal and Liferay DXP Vulnerable to XSS via the Layout Module
6.1
MEDIUM
CVSS 3.1
EPSS 0.22%
Description
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
How to fix CVE-2023-3193
To remediate CVE-2023-3193, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 7.4.3.74-ga74 or later
Is CVE-2023-3193 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 7.4.13.u70, <= 7.4.13.u73
- >= 7.4.3.70-ga70, < 7.4.3.74-ga74
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |