Vulnerability Details CVE-2023-33939
Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a facet label.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.5%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2023-33939
-
cpe:2.3:a:liferay:digital_experience_platform:7.1
-
cpe:2.3:a:liferay:digital_experience_platform:7.2
-
cpe:2.3:a:liferay:digital_experience_platform:7.3
-
cpe:2.3:a:liferay:digital_experience_platform:7.4
-
cpe:2.3:a:liferay:liferay_portal:7.1.0
-
cpe:2.3:a:liferay:liferay_portal:7.1.1
-
cpe:2.3:a:liferay:liferay_portal:7.1.2
-
cpe:2.3:a:liferay:liferay_portal:7.1.3
-
cpe:2.3:a:liferay:liferay_portal:7.2
-
cpe:2.3:a:liferay:liferay_portal:7.2.0
-
cpe:2.3:a:liferay:liferay_portal:7.2.1
-
cpe:2.3:a:liferay:liferay_portal:7.3
-
cpe:2.3:a:liferay:liferay_portal:7.3.0
-
cpe:2.3:a:liferay:liferay_portal:7.3.1
-
cpe:2.3:a:liferay:liferay_portal:7.3.2
-
cpe:2.3:a:liferay:liferay_portal:7.3.3
-
cpe:2.3:a:liferay:liferay_portal:7.3.4
-
cpe:2.3:a:liferay:liferay_portal:7.3.5
-
cpe:2.3:a:liferay:liferay_portal:7.3.6
-
cpe:2.3:a:liferay:liferay_portal:7.3.7
-
cpe:2.3:a:liferay:liferay_portal:7.4.0
-
cpe:2.3:a:liferay:liferay_portal:7.4.1
-
cpe:2.3:a:liferay:liferay_portal:7.4.2
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.10
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.11
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.12
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.4
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.5
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.6
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.7
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.8
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.9