Miggo Logo

CVE-2023-33941: Cross-site scripting in Liferay Portal

6.1

CVSS Score
3.1

Basic Information

EPSS Score
0.48428%
Published
5/24/2023
Updated
11/6/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
com.liferay.portal:release.portal.bommaven>= 7.4.3.41, < 7.4.3.537.4.3.53

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

Multipl* *ross-sit* s*riptin* (XSS) vuln*r**iliti*s in t** Plu*in *or O*ut* *.* mo*ul*'s O*ut**Provi**r*ppli**tionR**ir**t *l*ss in Li**r*y Port*l *.*.*.** t*rou** *.*.*.**, *n* Li**r*y *XP *.* up**t* ** t*rou** ** *llow r*mot* *tt**k*rs to inj**t *r

Reasoning

No *n*lysis *v*il**l*