Liferay Digital Experience Platform (DXP) 2023.q3.0

CPE Details

Liferay Digital Experience Platform (DXP) 2023.q3.0
2023.q3.0
2024-12-16
18h49 +00:00
2024-12-16
18h49 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:liferay:digital_experience_platform:2023.q3.0:*:*:*:*:*:*:*

Informations

Vendor

liferay

Product

digital_experience_platform

Version

2023.q3.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-47795 2024-02-21 14h01 +00:00 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
9
Critique
CVE-2023-40191 2024-02-21 03h06 +00:00 Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
9
Critique
CVE-2023-42498 2024-02-21 02h47 +00:00 Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
9.6
Critique
CVE-2024-26270 2024-02-20 13h43 +00:00 The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
6.5
Moyen
CVE-2023-44308 2024-02-20 06h29 +00:00 Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
6.1
Moyen
CVE-2023-5190 2024-02-20 06h03 +00:00 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter.
6.1
Moyen