Liferay DXP 7.4 Update 70

CPE Details

Liferay DXP 7.4 Update 70
7.4
2023-06-21
10h55 +00:00
2023-07-12
07h44 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:liferay:dxp:7.4:update_70:*:*:*:*:*:*

Informations

Vendor

liferay

Product

dxp

Version

7.4

Update

update_70

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-35030 2023-06-15 04h06 +00:00 Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
8.8
High
CVE-2023-35029 2023-06-15 03h59 +00:00 Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
6.1
Medium
CVE-2023-3193 2023-06-15 03h47 +00:00 Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
6.1
Medium