Опубликовано: 17 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 4.6
CVSS3: 6.1
Описание
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
Пакеты
Наименование
com.liferay.portal:release.portal.bom
maven
Затронутые версииВерсия исправления
>= 7.1.0, < 7.4.3.39
7.4.3.39
Наименование
com.liferay.portal:release.dxp.bom
maven
Затронутые версииВерсия исправления
>= 7.1, < 7.4.13.u39
7.4.13.u39
Связанные уязвимости
CVSS3: 6.1
nvd
около 1 года назад
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field