CVE-2023-37940
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2023-37940 is a cross-site scripting (XSS) vulnerability affecting various versions of Liferay Portal and DXP. This issue resides in the edit Service Access Policy page, allowing remote attackers to inject arbitrary web scripts or HTML into a service access policy's `Service Class` text field. Exploitation of this XSS flaw can lead to unintended execution of malicious code, potentially jeopardizing user sessions and data confidentiality within affected systems. Versions with known vulnerabilities include Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions. Organizations using these versions are advised to apply the necessary patches as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DXP
- Liferay Portal
Affected Vendors
- Liferay