Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by an incomplete fix in CVE-2023-33941.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-48667 Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class
Github GHSA Github GHSA GHSA-49gm-5685-8fxv Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published:

Updated: 2024-09-13T16:28:45.098Z

Reserved: 2023-09-28T11:23:54.829Z

Link: CVE-2023-44311

cve-icon Vulnrichment

Updated: 2024-08-02T19:59:51.988Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T10:15:09.947

Modified: 2024-11-21T08:25:38.623

Link: CVE-2023-44311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.