Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp68-5v39-r869

Опубликовано: 17 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.6

Описание

Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module

Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module before 4.0.35 from Liferay Portal (7.3.5 through 7.4.3.91), and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Address, (4) Shipping Address 2, (5) Shipping Address 3, (6) Shipping Zip, (7) Shipping City, (8) Shipping Region (9), Shipping Country, (10) Billing Name, (11) Billing Phone Number, (12) Billing Address, (13) Billing Address 2, (14) Billing Address 3, (15) Billing Zip, (16) Billing City, (17) Billing Region, (18) Billing Country, or (19) Region Code.

Пакеты

Наименование

com.liferay.commerce:com.liferay.commerce.address.content.web

maven
Затронутые версииВерсия исправления

< 4.0.35

4.0.35

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

>= 7.3.0, <= 7.3.10.u33

Отсутствует

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0, <= 7.4.13.u92

Отсутствует

EPSS

Процентиль: 43%
0.00208
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.6
nvd
больше 2 лет назад

Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Address, (4) Shipping Address 2, (5) Shipping Address 3, (6) Shipping Zip, (7) Shipping City, (8) Shipping Region (9), Shipping Country, (10) Billing Name, (11) Billing Phone Number, (12) Billing Address, (13) Billing Address 2, (14) Billing Address 3, (15) Billing Zip, (16) Billing City, (17) Billing Region, (18) Billing Country, or (19) Region Code.

EPSS

Процентиль: 43%
0.00208
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79