CVE-2023-37940

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 17, 2024
CWE ID 79

Summary

CVE-2023-37940 is a cross-site scripting (XSS) vulnerability affecting various versions of Liferay Portal and DXP. This issue resides in the edit Service Access Policy page, allowing remote attackers to inject arbitrary web scripts or HTML into a service access policy's `Service Class` text field. Exploitation of this XSS flaw can lead to unintended execution of malicious code, potentially jeopardizing user sessions and data confidentiality within affected systems. Versions with known vulnerabilities include Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions. Organizations using these versions are advised to apply the necessary patches as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share