Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0515 | Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter. |
Github GHSA |
GHSA-54pv-r62j-9qqc | Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 28 Jan 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay digital Experience Platform Liferay liferay Portal |
|
| CPEs | cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update16:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update17:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update26:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update27:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update28:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update29:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update30:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update31:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update9:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Liferay
Liferay digital Experience Platform Liferay liferay Portal |
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2024-08-02T19:23:39.433Z
Reserved: 2023-09-11T08:54:24.311Z
Link: CVE-2023-42496
Updated: 2024-08-02T19:23:39.433Z
Status : Analyzed
Published: 2024-02-21T03:15:08.057
Modified: 2025-01-28T02:54:33.753
Link: CVE-2023-42496
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA