Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update2"
},
{
"introduced": "7.4.0"
},
{
"last_affected": "7.4.3.30"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-33940.json"