CVE-2024-11993
17.12.2024, 21:15
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
| Vendor | Product | Version |
|---|---|---|
| liferay | liferay_portal | 7.1.0 ≤ 𝑥 < 7.4.3.39 |
| liferay | digital_experience_platform | 7.1 ≤ 𝑥 < 7.4 |
| liferay | digital_experience_platform | 7.4 |
| liferay | digital_experience_platform | 7.4:update1 |
| liferay | digital_experience_platform | 7.4:update10 |
| liferay | digital_experience_platform | 7.4:update11 |
| liferay | digital_experience_platform | 7.4:update12 |
| liferay | digital_experience_platform | 7.4:update13 |
| liferay | digital_experience_platform | 7.4:update14 |
| liferay | digital_experience_platform | 7.4:update15 |
| liferay | digital_experience_platform | 7.4:update16 |
| liferay | digital_experience_platform | 7.4:update17 |
| liferay | digital_experience_platform | 7.4:update18 |
| liferay | digital_experience_platform | 7.4:update19 |
| liferay | digital_experience_platform | 7.4:update2 |
| liferay | digital_experience_platform | 7.4:update20 |
| liferay | digital_experience_platform | 7.4:update21 |
| liferay | digital_experience_platform | 7.4:update22 |
| liferay | digital_experience_platform | 7.4:update23 |
| liferay | digital_experience_platform | 7.4:update24 |
| liferay | digital_experience_platform | 7.4:update25 |
| liferay | digital_experience_platform | 7.4:update26 |
| liferay | digital_experience_platform | 7.4:update27 |
| liferay | digital_experience_platform | 7.4:update28 |
| liferay | digital_experience_platform | 7.4:update29 |
| liferay | digital_experience_platform | 7.4:update3 |
| liferay | digital_experience_platform | 7.4:update30 |
| liferay | digital_experience_platform | 7.4:update31 |
| liferay | digital_experience_platform | 7.4:update32 |
| liferay | digital_experience_platform | 7.4:update33 |
| liferay | digital_experience_platform | 7.4:update34 |
| liferay | digital_experience_platform | 7.4:update35 |
| liferay | digital_experience_platform | 7.4:update36 |
| liferay | digital_experience_platform | 7.4:update37 |
| liferay | digital_experience_platform | 7.4:update38 |
| liferay | digital_experience_platform | 7.4:update4 |
| liferay | digital_experience_platform | 7.4:update5 |
| liferay | digital_experience_platform | 7.4:update6 |
| liferay | digital_experience_platform | 7.4:update7 |
| liferay | digital_experience_platform | 7.4:update8 |
| liferay | digital_experience_platform | 7.4:update9 |
𝑥
= Vulnerable software versions