GHSA-hv45-r2f5-fmhj

Suggest an improvement
Source
https://github.com/advisories/GHSA-hv45-r2f5-fmhj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-hv45-r2f5-fmhj/GHSA-hv45-r2f5-fmhj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hv45-r2f5-fmhj
Aliases
Published
2023-10-17T12:30:26Z
Modified
2025-07-29T13:27:25.423712Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget
Details

Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Wiki Web before 7.0.95 from Liferay Portal (7.1.0 through 7.4.3.87), and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's ‘Content’ text field.

Database specific
{
    "nvd_published_at": "2023-10-17T12:15:10Z",
    "github_reviewed_at": "2025-07-29T12:21:59Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true
}
References

Affected packages

Maven / com.liferay:com.liferay.wiki.web

Package

Name
com.liferay:com.liferay.wiki.web
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.wiki.web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.95

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11

2.*

2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.40

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.27
3.0.28
3.0.29
3.0.30
3.0.31
3.0.32
3.0.33
3.0.34
3.0.35
3.0.36
3.0.37
3.0.38
3.0.39
3.0.40
3.0.41
3.0.42
3.0.43
3.0.44
3.0.45
3.0.46
3.0.47
3.0.48
3.0.49
3.0.50
3.0.51
3.0.52
3.0.53
3.0.54
3.0.55
3.0.56
3.0.57
3.0.58
3.0.59
3.0.60
3.0.61
3.0.62
3.0.63
3.0.64
3.0.65
3.0.66
3.0.67
3.0.68
3.0.69
3.0.70
3.0.71
3.0.72
3.0.73
3.0.74
3.0.75
3.0.76
3.0.77
3.0.78
3.0.79
3.0.80
3.0.81
3.0.82
3.0.83
3.0.84
3.0.85
3.0.86
3.0.87
3.0.88
3.0.89
3.0.90
3.0.91
3.0.92
3.0.93
3.0.94
3.0.95
3.0.96
3.0.97
3.0.98

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.0.10
4.0.11
4.0.12
4.0.13
4.0.14
4.0.15
4.0.16
4.0.17
4.0.18
4.0.19
4.0.20
4.0.21
4.0.22
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.47
4.0.48
4.0.49
4.0.50
4.0.51
4.0.52
4.0.53
4.0.54
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.60
4.0.61
4.0.62
4.0.63
4.0.64
4.0.65
4.0.66
4.0.67
4.0.68
4.0.69
4.0.70
4.0.71
4.0.72
4.0.73
4.0.74
4.0.75
4.0.76
4.0.77
4.0.78
4.0.79
4.0.80
4.0.81
4.0.82
4.0.83
4.0.84
4.0.85
4.0.86
4.0.87
4.0.88
4.0.89
4.0.90
4.0.91
4.0.92
4.0.93
4.0.94
4.0.95
4.0.96
4.0.97
4.0.98
4.0.99
4.0.100
4.0.101
4.0.102
4.0.103
4.0.104
4.0.105
4.0.106
4.0.107
4.0.108
4.0.109
4.0.110
4.0.111

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.30
5.0.31
5.0.32
5.0.33
5.0.34
5.0.35
5.0.36
5.0.37
5.0.38
5.0.39
5.0.40
5.0.41
5.0.42
5.0.43
5.0.44
5.0.45
5.0.46
5.0.47
5.0.48
5.0.49
5.0.50
5.0.51
5.0.52
5.0.53
5.0.54
5.0.55
5.0.56
5.0.57
5.0.58
5.0.59
5.0.60
5.0.61
5.0.62
5.0.63
5.0.64
5.0.65
5.0.66
5.0.67
5.0.68
5.0.69
5.0.70
5.0.71
5.0.72
5.0.73
5.0.74
5.0.75
5.0.76
5.0.77
5.0.78
5.0.79
5.0.80
5.0.81
5.0.82
5.0.83
5.0.84
5.0.85
5.0.86
5.0.87
5.0.88
5.0.89
5.0.90
5.0.91
5.0.92
5.0.93
5.0.94
5.0.95
5.0.96
5.0.97
5.0.98
5.0.99
5.0.100
5.0.101
5.0.102
5.0.103
5.0.104
5.0.105
5.0.106
5.0.107
5.0.108
5.0.109
5.0.110

6.*

6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
6.0.10
6.0.11
6.0.12
6.0.13
6.0.14
6.0.15
6.0.16
6.0.17
6.0.18
6.0.19
6.0.20
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
6.0.26
6.0.27
6.0.28
6.0.29
6.0.30
6.0.31
6.0.32
6.0.33
6.0.34
6.0.35
6.0.36
6.0.37
6.0.38
6.0.39
6.0.40
6.0.41
6.0.42
6.0.43
6.0.44
6.0.45
6.0.46
6.0.47
6.0.48
6.0.49
6.0.50
6.0.51
6.0.52
6.0.53
6.0.54
6.0.55
6.0.56
6.0.57
6.0.58
6.0.59
6.0.60
6.0.61
6.0.62
6.0.63
6.0.64
6.0.65
6.0.66
6.0.67
6.0.68
6.0.69
6.0.70
6.0.71
6.0.72
6.0.73
6.0.74
6.0.75
6.0.76
6.0.77
6.0.78
6.0.79
6.0.80
6.0.81
6.0.82

7.*

7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25
7.0.26
7.0.27
7.0.28
7.0.29
7.0.30
7.0.31
7.0.32
7.0.33
7.0.34
7.0.35
7.0.36
7.0.37
7.0.38
7.0.39
7.0.40
7.0.41
7.0.42
7.0.43
7.0.44
7.0.45
7.0.46
7.0.47
7.0.48
7.0.49
7.0.50
7.0.51
7.0.52
7.0.53
7.0.54
7.0.55
7.0.56
7.0.57
7.0.58
7.0.59
7.0.60
7.0.61
7.0.62
7.0.63
7.0.64
7.0.65
7.0.66
7.0.67
7.0.68
7.0.69
7.0.70
7.0.71
7.0.72
7.0.73
7.0.74
7.0.75
7.0.76
7.0.77
7.0.78
7.0.79
7.0.80
7.0.81
7.0.82
7.0.83
7.0.84
7.0.85
7.0.86
7.0.87
7.0.88
7.0.89
7.0.90
7.0.91
7.0.92
7.0.93
7.0.94

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.10.fp83
Last affected
7.0.10.fp102

Affected versions

7.*

7.0.10.fp83
7.0.10.fp84
7.0.10.fp85
7.0.10.fp85-1
7.0.10.fp86
7.0.10.fp86-1
7.0.10.fp87
7.0.10.fp87-1
7.0.10.fp88
7.0.10.fp89
7.0.10.fp90
7.0.10.fp91
7.0.10.fp92
7.0.10.fp94
7.0.10.fp94-1
7.0.10.fp95
7.0.10.fp95-1
7.0.10.fp95-2
7.0.10.fp97
7.0.10.fp98
7.0.10.fp100
7.0.10.fp101
7.0.10.fp102

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Last affected
7.1.10.fp28

Affected versions

7.*

7.1.10
7.1.10.fp1
7.1.10.fp2
7.1.10.fp3
7.1.10.fp4
7.1.10.fp5
7.1.10.fp6
7.1.10.fp7
7.1.10.fp8
7.1.10.fp9
7.1.10.fp10
7.1.10.fp11
7.1.10.fp12
7.1.10.fp13
7.1.10.fp14
7.1.10.fp15
7.1.10.fp16
7.1.10.fp17
7.1.10.fp18
7.1.10.fp19
7.1.10.fp20
7.1.10.fp22
7.1.10.fp24
7.1.10.fp25
7.1.10.fp26
7.1.10.fp27
7.1.10.fp28

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.0
Last affected
7.2.10.fp20

Affected versions

7.*

7.2.1
7.2.10
7.2.10.fp1
7.2.10.fp1-1
7.2.10.fp2
7.2.10.fp3
7.2.10.fp4
7.2.10.fp5
7.2.10.fp6
7.2.10.fp7
7.2.10.fp8
7.2.10.fp9
7.2.10.fp10
7.2.10.fp11
7.2.10.fp12
7.2.10.fp13
7.2.10.fp14
7.2.10.fp15
7.2.10.fp16
7.2.10.fp17
7.2.10.fp18
7.2.10.fp19
7.2.10.fp20

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.3.0
Fixed
7.3.10.u34

Affected versions

7.*

7.3.10
7.3.10.ep3
7.3.10.ep4
7.3.10.ep5
7.3.10.fp1
7.3.10.fp2
7.3.10.u4
7.3.10.u5
7.3.10.u6
7.3.10.u7
7.3.10.u8
7.3.10.u9
7.3.10.u10
7.3.10.u11
7.3.10.u12
7.3.10.u13
7.3.10.u14
7.3.10.u15
7.3.10.u16
7.3.10.u17
7.3.10.u18
7.3.10.u19
7.3.10.u19-1
7.3.10.u20
7.3.10.u20-1
7.3.10.u21
7.3.10.u21-1
7.3.10.u22
7.3.10.u22-1
7.3.10.u23
7.3.10.u24
7.3.10.u25
7.3.10.u26
7.3.10.u27
7.3.10.u28
7.3.10.u29
7.3.10.u30
7.3.10.u31
7.3.10.u32
7.3.10.u33

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.4.0
Fixed
7.4.13.u88

Affected versions

7.*

7.4.10.ep1
7.4.11
7.4.12
7.4.13
7.4.13.u1
7.4.13.u2
7.4.13.u3
7.4.13.u4
7.4.13.u5
7.4.13.u6
7.4.13.u7
7.4.13.u8
7.4.13.u9
7.4.13.u10
7.4.13.u15
7.4.13.u16
7.4.13.u17
7.4.13.u18
7.4.13.u19
7.4.13.u20
7.4.13.u21
7.4.13.u22
7.4.13.u23
7.4.13.u24
7.4.13.u25
7.4.13.u26
7.4.13.u27
7.4.13.u28
7.4.13.u29
7.4.13.u30
7.4.13.u31
7.4.13.u32
7.4.13.u33
7.4.13.u34
7.4.13.u35
7.4.13.u36
7.4.13.u37
7.4.13.u38
7.4.13.u39
7.4.13.u40
7.4.13.u41
7.4.13.u42
7.4.13.u43
7.4.13.u44
7.4.13.u45
7.4.13.u46
7.4.13.u47
7.4.13.u48
7.4.13.u49
7.4.13.u50
7.4.13.u51
7.4.13.u52
7.4.13.u53
7.4.13.u54
7.4.13.u55
7.4.13.u56
7.4.13.u57
7.4.13.u58
7.4.13.u59
7.4.13.u60
7.4.13.u61
7.4.13.u62
7.4.13.u63
7.4.13.u64
7.4.13.u65
7.4.13.u66
7.4.13.u67
7.4.13.u68
7.4.13.u69
7.4.13.u70
7.4.13.u71
7.4.13.u72
7.4.13.u73
7.4.13.u74
7.4.13.u75
7.4.13.u76
7.4.13.u77
7.4.13.u78
7.4.13.u79
7.4.13.u80
7.4.13.u81
7.4.13.u82
7.4.13.u83
7.4.13.u84
7.4.13.u85
7.4.13.u86
7.4.13.u87