CVE-2023-42629
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9epss 2.2%
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
public PoCs found — 1
cve_referencewww.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.