Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-658f-xhv4-p978

Опубликовано: 16 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Liferay Portal and Liferay DXP allows arbitrary injection via form field

Multiple cross-site scripting (XSS) vulnerabilities in Dynamic Data Mapping Form Field Type before 6.0.11 from Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.

Пакеты

Наименование

com.liferay:com.liferay.dynamic.data.mapping.form.field.type

maven
Затронутые версииВерсия исправления

< 6.0.11

6.0.11

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

>= 7.3.0, < 7.3.10.fp3

7.3.10.fp3

EPSS

Процентиль: 49%
0.00257
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.

EPSS

Процентиль: 49%
0.00257
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79