{"id":"GHSA-j663-6jpj-xx8c","summary":"Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components","details":"Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components before 3.0.25 from Liferay Portal (7.4.2 through 7.4.3.53), and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.","aliases":["BIT-liferay-2023-44309","CVE-2023-44309"],"modified":"2025-08-08T22:12:01.320308Z","published":"2023-10-17T09:30:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-08-08T21:14:55Z","nvd_published_at":"2023-10-17T09:15:10Z","cwe_ids":["CWE-79"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44309"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/1287c68486d60b87179995d8b8bd530031300a47"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/28f8a7aabccce45e9d60cfb0cf63fc53c99b0d26"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/9031a7a03e5891e7ccf762011fe8bcc2e433b1db"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/ba628735cfae8656ab4243ecffce260413ed2460"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/d70fecd2c5709d8dd5f4992b408a640ce912001b"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/e45bf2d00ed7f95f02702a1da3e4115ab30b1bff"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/ed856dd9e2947e3e660d7cfbdb8c604b296db790"},{"type":"PACKAGE","url":"https://github.com/liferay/liferay-portal"},{"type":"WEB","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-44309"}],"affected":[{"package":{"name":"com.liferay:com.liferay.fragment.entry.processor.impl","ecosystem":"Maven","purl":"pkg:maven/com.liferay/com.liferay.fragment.entry.processor.impl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.25"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","3.0.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.15","3.0.16","3.0.17","3.0.18","3.0.19","3.0.2","3.0.20","3.0.21","3.0.22","3.0.23","3.0.24","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json"}},{"package":{"name":"com.liferay.portal:release.dxp.bom","ecosystem":"Maven","purl":"pkg:maven/com.liferay.portal/release.dxp.bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.4.0"},{"fixed":"7.4.13.u54"}]}],"versions":["7.4.10.ep1","7.4.11","7.4.12","7.4.13","7.4.13.u1","7.4.13.u10","7.4.13.u15","7.4.13.u16","7.4.13.u17","7.4.13.u18","7.4.13.u19","7.4.13.u2","7.4.13.u20","7.4.13.u21","7.4.13.u22","7.4.13.u23","7.4.13.u24","7.4.13.u25","7.4.13.u26","7.4.13.u27","7.4.13.u28","7.4.13.u29","7.4.13.u3","7.4.13.u30","7.4.13.u31","7.4.13.u32","7.4.13.u33","7.4.13.u34","7.4.13.u35","7.4.13.u36","7.4.13.u37","7.4.13.u38","7.4.13.u39","7.4.13.u4","7.4.13.u40","7.4.13.u41","7.4.13.u42","7.4.13.u43","7.4.13.u44","7.4.13.u45","7.4.13.u46","7.4.13.u47","7.4.13.u48","7.4.13.u49","7.4.13.u5","7.4.13.u50","7.4.13.u51","7.4.13.u52","7.4.13.u53","7.4.13.u6","7.4.13.u7","7.4.13.u8","7.4.13.u9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}