{"id":"CVE-2023-47797","details":"Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.","aliases":["GHSA-v32m-pf9q-p3xg"],"modified":"2026-09-05T08:10:14.130745Z","published":"2023-11-17T06:15:34.230Z","references":[{"type":"ADVISORY","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47797"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"b77647a3103c2ab46593d454768502a6b7715e20"},{"last_affected":"2bb54c6fa9f6fac206d73d262bb2e027472216ac"}],"database_specific":{"cpe":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.4.3.94"},{"last_affected":"7.4.3.95"}],"source":"CPE_RANGE"}}],"versions":["7.4.3.95-ga95","7.4.3.94-ga94"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-47797.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}