Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3606 | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field. |
Github GHSA |
GHSA-px38-239g-x5mg | Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 28 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay digital Experience Platform Liferay liferay Portal |
|
| CPEs | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update16:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update17:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update26:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update27:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update28:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update29:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update9:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Liferay
Liferay digital Experience Platform Liferay liferay Portal |
Tue, 17 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Dec 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2024-12-17T21:41:38.543Z
Reserved: 2023-07-11T09:17:17.552Z
Link: CVE-2023-37940
Updated: 2024-12-17T21:41:34.805Z
Status : Analyzed
Published: 2024-12-17T22:15:05.080
Modified: 2025-01-28T21:18:48.497
Link: CVE-2023-37940
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA