CVE-2023-42628
17.10.2023, 12:15
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's Content text field.
Vendor | Product | Version |
---|---|---|
liferay | digital_experience_platform | 7.0 |
liferay | digital_experience_platform | 7.0:fix_pack_1 |
liferay | digital_experience_platform | 7.0:fix_pack_10 |
liferay | digital_experience_platform | 7.0:fix_pack_11 |
liferay | digital_experience_platform | 7.0:fix_pack_12 |
liferay | digital_experience_platform | 7.0:fix_pack_13 |
liferay | digital_experience_platform | 7.0:fix_pack_14 |
liferay | digital_experience_platform | 7.0:fix_pack_15 |
liferay | digital_experience_platform | 7.0:fix_pack_16 |
liferay | digital_experience_platform | 7.0:fix_pack_17 |
liferay | digital_experience_platform | 7.0:fix_pack_18 |
liferay | digital_experience_platform | 7.0:fix_pack_19 |
liferay | digital_experience_platform | 7.0:fix_pack_2 |
liferay | digital_experience_platform | 7.0:fix_pack_20 |
liferay | digital_experience_platform | 7.0:fix_pack_21 |
liferay | digital_experience_platform | 7.0:fix_pack_22 |
liferay | digital_experience_platform | 7.0:fix_pack_23 |
liferay | digital_experience_platform | 7.0:fix_pack_24 |
liferay | digital_experience_platform | 7.0:fix_pack_25 |
liferay | digital_experience_platform | 7.0:fix_pack_26 |
liferay | digital_experience_platform | 7.0:fix_pack_27 |
liferay | digital_experience_platform | 7.0:fix_pack_28 |
liferay | digital_experience_platform | 7.0:fix_pack_29 |
liferay | digital_experience_platform | 7.0:fix_pack_3 |
liferay | digital_experience_platform | 7.0:fix_pack_30 |
liferay | digital_experience_platform | 7.0:fix_pack_31 |
liferay | digital_experience_platform | 7.0:fix_pack_32 |
liferay | digital_experience_platform | 7.0:fix_pack_33 |
liferay | digital_experience_platform | 7.0:fix_pack_34 |
liferay | digital_experience_platform | 7.0:fix_pack_35 |
liferay | digital_experience_platform | 7.0:fix_pack_36 |
liferay | digital_experience_platform | 7.0:fix_pack_37 |
liferay | digital_experience_platform | 7.0:fix_pack_38 |
liferay | digital_experience_platform | 7.0:fix_pack_39 |
liferay | digital_experience_platform | 7.0:fix_pack_4 |
liferay | digital_experience_platform | 7.0:fix_pack_40 |
liferay | digital_experience_platform | 7.0:fix_pack_41 |
liferay | digital_experience_platform | 7.0:fix_pack_42 |
liferay | digital_experience_platform | 7.0:fix_pack_43 |
liferay | digital_experience_platform | 7.0:fix_pack_44 |
liferay | digital_experience_platform | 7.0:fix_pack_45 |
liferay | digital_experience_platform | 7.0:fix_pack_46 |
liferay | digital_experience_platform | 7.0:fix_pack_47 |
liferay | digital_experience_platform | 7.0:fix_pack_48 |
liferay | digital_experience_platform | 7.0:fix_pack_49 |
liferay | digital_experience_platform | 7.0:fix_pack_5 |
liferay | digital_experience_platform | 7.0:fix_pack_50 |
liferay | digital_experience_platform | 7.0:fix_pack_51 |
liferay | digital_experience_platform | 7.0:fix_pack_52 |
liferay | digital_experience_platform | 7.0:fix_pack_53 |
liferay | digital_experience_platform | 7.0:fix_pack_54 |
liferay | digital_experience_platform | 7.0:fix_pack_55 |
liferay | digital_experience_platform | 7.0:fix_pack_56 |
liferay | digital_experience_platform | 7.0:fix_pack_57 |
liferay | digital_experience_platform | 7.0:fix_pack_58 |
liferay | digital_experience_platform | 7.0:fix_pack_59 |
liferay | digital_experience_platform | 7.0:fix_pack_6 |
liferay | digital_experience_platform | 7.0:fix_pack_60 |
liferay | digital_experience_platform | 7.0:fix_pack_61 |
liferay | digital_experience_platform | 7.0:fix_pack_62 |
liferay | digital_experience_platform | 7.0:fix_pack_63 |
liferay | digital_experience_platform | 7.0:fix_pack_64 |
liferay | digital_experience_platform | 7.0:fix_pack_65 |
liferay | digital_experience_platform | 7.0:fix_pack_66 |
liferay | digital_experience_platform | 7.0:fix_pack_67 |
liferay | digital_experience_platform | 7.0:fix_pack_68 |
liferay | digital_experience_platform | 7.0:fix_pack_69 |
liferay | digital_experience_platform | 7.0:fix_pack_7 |
liferay | digital_experience_platform | 7.0:fix_pack_70 |
liferay | digital_experience_platform | 7.0:fix_pack_71 |
liferay | digital_experience_platform | 7.0:fix_pack_72 |
liferay | digital_experience_platform | 7.0:fix_pack_73 |
liferay | digital_experience_platform | 7.0:fix_pack_74 |
liferay | digital_experience_platform | 7.0:fix_pack_75 |
liferay | digital_experience_platform | 7.0:fix_pack_76 |
liferay | digital_experience_platform | 7.0:fix_pack_77 |
liferay | digital_experience_platform | 7.0:fix_pack_78 |
liferay | digital_experience_platform | 7.0:fix_pack_79 |
liferay | digital_experience_platform | 7.0:fix_pack_8 |
liferay | digital_experience_platform | 7.0:fix_pack_80 |
liferay | digital_experience_platform | 7.0:fix_pack_81 |
liferay | digital_experience_platform | 7.0:fix_pack_82 |
liferay | digital_experience_platform | 7.1 |
liferay | digital_experience_platform | 7.2 |
liferay | digital_experience_platform | 7.3 |
liferay | digital_experience_platform | 7.4 |
liferay | digital_experience_platform | 7.4:update1 |
liferay | digital_experience_platform | 7.4:update21 |
liferay | digital_experience_platform | 7.4:update34 |
liferay | digital_experience_platform | 7.4:update36 |
liferay | digital_experience_platform | 7.4:update41 |
liferay | digital_experience_platform | 7.4:update48 |
liferay | digital_experience_platform | 7.4:update50 |
liferay | digital_experience_platform | 7.4:update52 |
liferay | digital_experience_platform | 7.4:update62 |
liferay | digital_experience_platform | 7.4:update67 |
liferay | digital_experience_platform | 7.4:update76 |
liferay | digital_experience_platform | 7.4:update81 |
liferay | digital_experience_platform | 7.4:update82 |
liferay | digital_experience_platform | 7.4:update83 |
liferay | digital_experience_platform | 7.4:update84 |
liferay | digital_experience_platform | 7.4:update85 |
liferay | digital_experience_platform | 7.4:update86 |
liferay | liferay_portal | 7.1.0 ≤ 𝑥 < 7.4.3.88 |
𝑥
= Vulnerable software versions
References