Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
History

Tue, 22 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2023-05-24T14:36:07.977Z

Updated: 2024-10-22T15:52:26.805Z

Reserved: 2023-05-24T02:36:00.163Z

Link: CVE-2023-33941

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:13.782Z

cve-icon NVD

Status : Modified

Published: 2023-05-24T15:15:09.697

Modified: 2024-11-21T08:06:15.363

Link: CVE-2023-33941

cve-icon Redhat

No data.