logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-42628

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-42628

Description:
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's ‘Content’ text field.
Last updated date:
12/28/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/28/2023
Reference url to background

https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy