CVE-2023-44310

Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
LiferayCNA
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
liferaydigital_experience_platform
7.1:fix_pack_1
liferaydigital_experience_platform
7.1:fix_pack_10
liferaydigital_experience_platform
7.1:fix_pack_11
liferaydigital_experience_platform
7.1:fix_pack_12
liferaydigital_experience_platform
7.1:fix_pack_13
liferaydigital_experience_platform
7.1:fix_pack_14
liferaydigital_experience_platform
7.1:fix_pack_15
liferaydigital_experience_platform
7.1:fix_pack_16
liferaydigital_experience_platform
7.1:fix_pack_17
liferaydigital_experience_platform
7.1:fix_pack_18
liferaydigital_experience_platform
7.1:fix_pack_19
liferaydigital_experience_platform
7.1:fix_pack_2
liferaydigital_experience_platform
7.1:fix_pack_20
liferaydigital_experience_platform
7.1:fix_pack_21
liferaydigital_experience_platform
7.1:fix_pack_22
liferaydigital_experience_platform
7.1:fix_pack_23
liferaydigital_experience_platform
7.1:fix_pack_3
liferaydigital_experience_platform
7.1:fix_pack_4
liferaydigital_experience_platform
7.1:fix_pack_5
liferaydigital_experience_platform
7.1:fix_pack_6
liferaydigital_experience_platform
7.1:fix_pack_7
liferaydigital_experience_platform
7.1:fix_pack_8
liferaydigital_experience_platform
7.1:fix_pack_9
liferaydigital_experience_platform
7.4
liferaydigital_experience_platform
7.4:update1
liferaydigital_experience_platform
7.4:update21
liferaydigital_experience_platform
7.4:update34
liferaydigital_experience_platform
7.4:update36
liferaydigital_experience_platform
7.4:update41
liferaydigital_experience_platform
7.4:update48
liferaydigital_experience_platform
7.4:update50
liferaydigital_experience_platform
7.4:update52
liferaydigital_experience_platform
7.4:update62
liferaydigital_experience_platform
7.4:update67
liferaydigital_experience_platform
7.4:update76
liferayliferay_portal
7.3.6 ≤
𝑥
< 7.4.3.49
𝑥
= Vulnerable software versions