Reflected cross-site scripting (XSS) vulnerability in the Language Override edit...
Vulnerability Description
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42498
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Amin ACHOUR
More from Liferay
View All →Affected Vendor
Liferay
View all reports →