CVE-2023-33943

EUVD-2023-1595
Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job Title text field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
LiferayCNA
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
liferaydigital_experience_platform
7.4:update21
liferaydigital_experience_platform
7.4:update22
liferaydigital_experience_platform
7.4:update23
liferaydigital_experience_platform
7.4:update24
liferaydigital_experience_platform
7.4:update25
liferaydigital_experience_platform
7.4:update26
liferaydigital_experience_platform
7.4:update27
liferaydigital_experience_platform
7.4:update28
liferaydigital_experience_platform
7.4:update29
liferaydigital_experience_platform
7.4:update30
liferaydigital_experience_platform
7.4:update31
liferaydigital_experience_platform
7.4:update32
liferaydigital_experience_platform
7.4:update33
liferaydigital_experience_platform
7.4:update34
liferaydigital_experience_platform
7.4:update35
liferaydigital_experience_platform
7.4:update36
liferaydigital_experience_platform
7.4:update37
liferaydigital_experience_platform
7.4:update38
liferaydigital_experience_platform
7.4:update39
liferaydigital_experience_platform
7.4:update40
liferaydigital_experience_platform
7.4:update41
liferaydigital_experience_platform
7.4:update42
liferaydigital_experience_platform
7.4:update43
liferaydigital_experience_platform
7.4:update44
liferaydigital_experience_platform
7.4:update45
liferaydigital_experience_platform
7.4:update46
liferaydigital_experience_platform
7.4:update47
liferaydigital_experience_platform
7.4:update48
liferaydigital_experience_platform
7.4:update49
liferaydigital_experience_platform
7.4:update50
liferaydigital_experience_platform
7.4:update51
liferaydigital_experience_platform
7.4:update52
liferaydigital_experience_platform
7.4:update53
liferaydigital_experience_platform
7.4:update54
liferaydigital_experience_platform
7.4:update55
liferaydigital_experience_platform
7.4:update56
liferaydigital_experience_platform
7.4:update57
liferaydigital_experience_platform
7.4:update58
liferaydigital_experience_platform
7.4:update59
liferaydigital_experience_platform
7.4:update60
liferaydigital_experience_platform
7.4:update61
liferaydigital_experience_platform
7.4:update62
liferayliferay_portal
7.4.3.21 ≤
𝑥
≤ 7.4.3.62
𝑥
= Vulnerable software versions