GHSA-cr36-3vqf-x5w5

Suggest an improvement
Source
https://github.com/advisories/GHSA-cr36-3vqf-x5w5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cr36-3vqf-x5w5
Aliases
Published
2024-02-21T03:30:37Z
Modified
2024-02-21T23:56:59Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting
Details

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-02-21T23:29:35Z",
    "nvd_published_at":  "2024-02-21T02:15:30Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Maven
com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
7.4.2

Affected versions

7.*
7.0.6
7.0.6-1
7.0.6-2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.3-1
7.2.0
7.2.1
7.2.1-1
7.3.0
7.3.0-1
7.3.1
7.3.1-1
7.3.2
7.3.2-1
7.3.3
7.3.3-1
7.3.4
7.3.5
7.3.6
7.3.7
7.4.0
7.4.1
7.4.1-1
7.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json"
com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.3.0
Fixed
7.3.10.u4

Affected versions

7.*
7.3.10
7.3.10.ep3
7.3.10.ep4
7.3.10.ep5
7.3.10.fp1
7.3.10.fp2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json"
com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.10.fp17

Affected versions

7.*
7.2.1
7.2.10
7.2.10.fp1
7.2.10.fp1-1
7.2.10.fp2
7.2.10.fp3
7.2.10.fp4
7.2.10.fp5
7.2.10.fp6
7.2.10.fp7
7.2.10.fp8
7.2.10.fp9
7.2.10.fp10
7.2.10.fp11
7.2.10.fp12
7.2.10.fp13
7.2.10.fp14
7.2.10.fp15
7.2.10.fp16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json"