Логотип exploitDog
bind:CVE-2023-44311
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-44311

Количество 2

Количество 2

nvd логотип

CVE-2023-44311

больше 2 лет назад

Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-49gm-5685-8fxv

больше 2 лет назад

Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-44311

Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.

CVSS3: 9.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-49gm-5685-8fxv

Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class

CVSS3: 9.6
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу