Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Address, (4) Shipping Address 2, (5) Shipping Address 3, (6) Shipping Zip, (7) Shipping City, (8) Shipping Region (9), Shipping Country, (10) Billing Name, (11) Billing Phone Number, (12) Billing Address, (13) Billing Address 2, (14) Billing Address 3, (15) Billing Zip, (16) Billing City, (17) Billing Region, (18) Billing Country, or (19) Region Code.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-47060 Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module
Github GHSA Github GHSA GHSA-qp68-5v39-r869 Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published:

Updated: 2025-06-12T15:09:49.651Z

Reserved: 2023-09-12T05:35:42.826Z

Link: CVE-2023-42627

cve-icon Vulnrichment

Updated: 2024-08-02T19:23:39.907Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T13:15:11.677

Modified: 2024-11-21T08:22:50.247

Link: CVE-2023-42627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.