Critical severityNVD Advisory· Published Oct 17, 2023· Updated Aug 2, 2024
CVE-2023-42629
CVE-2023-42629
Description
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay:com.liferay.asset.categories.admin.webMaven | < 5.0.87 | 5.0.87 |
com.liferay.portal:release.dxp.bomMaven | >= 7.4.0, < 7.4.13.u88 | 7.4.13.u88 |
Affected products
2- Liferay/DXPv5Range: 7.4.13
Patches
12e02110747ddLPS-191047 Escape description
1 file changed · +1 −1
modules/apps/asset/asset-categories-admin-web/src/main/resources/META-INF/resources/view.jsp+1 −1 modified@@ -263,7 +263,7 @@ <c:if test="<%= Validator.isNotNull(description) %>"> <div class="mb-2"> <span class="mr-1"><liferay-ui:message key="description" />:</span> - <span class="text-break text-secondary"><%= description %></span> + <span class="text-break text-secondary"><%= HtmlUtil.escape(description) %></span> </div> </c:if> </div>
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
6- www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/mitreexploitthird-party-advisory
- github.com/advisories/GHSA-g44j-f8wm-6622ghsaADVISORY
- liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42629ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-42629ghsaADVISORY
- github.com/liferay/liferay-portal/commit/2e02110747dd5cccb978623545bfa1f3ad0a5602ghsaWEB
- www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portalghsaWEB
News mentions
0No linked articles in our index yet.