CVE-2023-44309
Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components
9.0
CRITICAL
CVSS 3.1
EPSS 0.20%
Description
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components before 3.0.25 from Liferay Portal (7.4.2 through 7.4.3.53), and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
How to fix CVE-2023-44309
To remediate CVE-2023-44309, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 3.0.25 or later
- —upgrade to 7.4.13.u54 or later
Is CVE-2023-44309 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 7.4.0, <= 7.4.0 | >= 7.4-update1.0, <= 7.4-update1.0, >= 7.4-update21.0, <= 7.4-update21.0, >= 7.4-update34.0, <= 7.4-update34.0, >= 7.4-update36.0, <= 7.4-update36.0, >= 7.4-update41.0, <= 7.4-update41.0, >= 7.4-update48.0, <= 7.4-update48.0, >= 7.4-update50.0, <= 7.4-update50.0, >= 7.4-update52.0, <= 7.4-update52.0
- from 0, < 3.0.25
- >= 7.4.0, < 7.4.13.u54
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |