Liferay Digital Experience Platform (DXP) 2023.q3.0

CPE Details

Liferay Digital Experience Platform (DXP) 2023.q3.0
2023.q3.0
2024-12-16
18h49 +00:00
2024-12-16
18h49 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:liferay:digital_experience_platform:2023.q3.0:*:*:*:*:*:*:*

Informations

Vendor

liferay

Product

digital_experience_platform

Version

2023.q3.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-47795 2024-02-21 14h01 +00:00 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
9
Critical
CVE-2023-40191 2024-02-21 03h06 +00:00 Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
9
Critical
CVE-2023-42498 2024-02-21 02h47 +00:00 Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
9.6
Critical
CVE-2024-26270 2024-02-20 13h43 +00:00 The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
6.5
Medium
CVE-2023-44308 2024-02-20 06h29 +00:00 Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
6.1
Medium
CVE-2023-5190 2024-02-20 06h03 +00:00 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.
6.1
Medium