GHSA-w2g3-j73q-7qv7
CRITICALCVE-2023-42497Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page before 2.0.86 from Liferay Portal (7.4.3.4 through 7.4.3.85), and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the comliferaytranslationwebinternalportletTranslationPortletredirect parameter.
- Affected
- < 2.0.86
- Fixed in
- 2.0.86
- Weakness
- CWE-79
- Published
- 2023-10-17
- Source
- github