{"id":"GHSA-v32m-pf9q-p3xg","summary":"Liferay Portal XSS with `p_l_back_url_title` on edit content page","details":"Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.","aliases":["CVE-2023-47797"],"modified":"2024-02-16T08:13:05.151406Z","published":"2023-11-17T06:31:22Z","database_specific":{"github_reviewed_at":"2023-11-24T16:53:34Z","nvd_published_at":"2023-11-17T06:15:34Z","cwe_ids":["CWE-79"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47797"},{"type":"WEB","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47797"}],"affected":[{"package":{"name":"com.liferay.portal:release.portal.bom","ecosystem":"Maven","purl":"pkg:maven/com.liferay.portal/release.portal.bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.4.3.94"},{"fixed":"7.4.3.96"}]}],"versions":["7.4.3.94","7.4.3.95","7.4.3.95-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-v32m-pf9q-p3xg/GHSA-v32m-pf9q-p3xg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}