CVE-2023-42628

Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's Content text field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
LiferayCNA
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
liferaydigital_experience_platform
7.0
liferaydigital_experience_platform
7.0:fix_pack_1
liferaydigital_experience_platform
7.0:fix_pack_10
liferaydigital_experience_platform
7.0:fix_pack_11
liferaydigital_experience_platform
7.0:fix_pack_12
liferaydigital_experience_platform
7.0:fix_pack_13
liferaydigital_experience_platform
7.0:fix_pack_14
liferaydigital_experience_platform
7.0:fix_pack_15
liferaydigital_experience_platform
7.0:fix_pack_16
liferaydigital_experience_platform
7.0:fix_pack_17
liferaydigital_experience_platform
7.0:fix_pack_18
liferaydigital_experience_platform
7.0:fix_pack_19
liferaydigital_experience_platform
7.0:fix_pack_2
liferaydigital_experience_platform
7.0:fix_pack_20
liferaydigital_experience_platform
7.0:fix_pack_21
liferaydigital_experience_platform
7.0:fix_pack_22
liferaydigital_experience_platform
7.0:fix_pack_23
liferaydigital_experience_platform
7.0:fix_pack_24
liferaydigital_experience_platform
7.0:fix_pack_25
liferaydigital_experience_platform
7.0:fix_pack_26
liferaydigital_experience_platform
7.0:fix_pack_27
liferaydigital_experience_platform
7.0:fix_pack_28
liferaydigital_experience_platform
7.0:fix_pack_29
liferaydigital_experience_platform
7.0:fix_pack_3
liferaydigital_experience_platform
7.0:fix_pack_30
liferaydigital_experience_platform
7.0:fix_pack_31
liferaydigital_experience_platform
7.0:fix_pack_32
liferaydigital_experience_platform
7.0:fix_pack_33
liferaydigital_experience_platform
7.0:fix_pack_34
liferaydigital_experience_platform
7.0:fix_pack_35
liferaydigital_experience_platform
7.0:fix_pack_36
liferaydigital_experience_platform
7.0:fix_pack_37
liferaydigital_experience_platform
7.0:fix_pack_38
liferaydigital_experience_platform
7.0:fix_pack_39
liferaydigital_experience_platform
7.0:fix_pack_4
liferaydigital_experience_platform
7.0:fix_pack_40
liferaydigital_experience_platform
7.0:fix_pack_41
liferaydigital_experience_platform
7.0:fix_pack_42
liferaydigital_experience_platform
7.0:fix_pack_43
liferaydigital_experience_platform
7.0:fix_pack_44
liferaydigital_experience_platform
7.0:fix_pack_45
liferaydigital_experience_platform
7.0:fix_pack_46
liferaydigital_experience_platform
7.0:fix_pack_47
liferaydigital_experience_platform
7.0:fix_pack_48
liferaydigital_experience_platform
7.0:fix_pack_49
liferaydigital_experience_platform
7.0:fix_pack_5
liferaydigital_experience_platform
7.0:fix_pack_50
liferaydigital_experience_platform
7.0:fix_pack_51
liferaydigital_experience_platform
7.0:fix_pack_52
liferaydigital_experience_platform
7.0:fix_pack_53
liferaydigital_experience_platform
7.0:fix_pack_54
liferaydigital_experience_platform
7.0:fix_pack_55
liferaydigital_experience_platform
7.0:fix_pack_56
liferaydigital_experience_platform
7.0:fix_pack_57
liferaydigital_experience_platform
7.0:fix_pack_58
liferaydigital_experience_platform
7.0:fix_pack_59
liferaydigital_experience_platform
7.0:fix_pack_6
liferaydigital_experience_platform
7.0:fix_pack_60
liferaydigital_experience_platform
7.0:fix_pack_61
liferaydigital_experience_platform
7.0:fix_pack_62
liferaydigital_experience_platform
7.0:fix_pack_63
liferaydigital_experience_platform
7.0:fix_pack_64
liferaydigital_experience_platform
7.0:fix_pack_65
liferaydigital_experience_platform
7.0:fix_pack_66
liferaydigital_experience_platform
7.0:fix_pack_67
liferaydigital_experience_platform
7.0:fix_pack_68
liferaydigital_experience_platform
7.0:fix_pack_69
liferaydigital_experience_platform
7.0:fix_pack_7
liferaydigital_experience_platform
7.0:fix_pack_70
liferaydigital_experience_platform
7.0:fix_pack_71
liferaydigital_experience_platform
7.0:fix_pack_72
liferaydigital_experience_platform
7.0:fix_pack_73
liferaydigital_experience_platform
7.0:fix_pack_74
liferaydigital_experience_platform
7.0:fix_pack_75
liferaydigital_experience_platform
7.0:fix_pack_76
liferaydigital_experience_platform
7.0:fix_pack_77
liferaydigital_experience_platform
7.0:fix_pack_78
liferaydigital_experience_platform
7.0:fix_pack_79
liferaydigital_experience_platform
7.0:fix_pack_8
liferaydigital_experience_platform
7.0:fix_pack_80
liferaydigital_experience_platform
7.0:fix_pack_81
liferaydigital_experience_platform
7.0:fix_pack_82
liferaydigital_experience_platform
7.1
liferaydigital_experience_platform
7.2
liferaydigital_experience_platform
7.3
liferaydigital_experience_platform
7.4
liferaydigital_experience_platform
7.4:update1
liferaydigital_experience_platform
7.4:update21
liferaydigital_experience_platform
7.4:update34
liferaydigital_experience_platform
7.4:update36
liferaydigital_experience_platform
7.4:update41
liferaydigital_experience_platform
7.4:update48
liferaydigital_experience_platform
7.4:update50
liferaydigital_experience_platform
7.4:update52
liferaydigital_experience_platform
7.4:update62
liferaydigital_experience_platform
7.4:update67
liferaydigital_experience_platform
7.4:update76
liferaydigital_experience_platform
7.4:update81
liferaydigital_experience_platform
7.4:update82
liferaydigital_experience_platform
7.4:update83
liferaydigital_experience_platform
7.4:update84
liferaydigital_experience_platform
7.4:update85
liferaydigital_experience_platform
7.4:update86
liferayliferay_portal
7.1.0 ≤
𝑥
< 7.4.3.88
𝑥
= Vulnerable software versions