Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's Service Class text field.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-fix_pack_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-fix_pack_2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-service_pack_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-service_pack_3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update4"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update5"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update6"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update7"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update2"
}
]
}[
{
"events": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.4.3.88"
}
]
},
{
"events": [
{
"introduced": "7.0"
},
{
"fixed": "7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update36"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update37"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update40"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update41"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update42"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update43"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update44"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update45"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update46"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update47"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update48"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update49"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update50"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update51"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update52"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update53"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update54"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update55"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update56"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update57"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update59"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update60"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update61"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update62"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update63"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update65"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update66"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update67"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update68"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update69"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update70"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update71"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update72"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update73"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update74"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update75"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update76"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update77"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update78"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update79"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update80"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update81"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update82"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update83"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update84"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update85"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update86"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update87"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37940.json"