{"id":"GHSA-v6m2-j92j-2h78","summary":"Cross-site scripting in Liferay Portal","details":"Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field. ","aliases":["BIT-liferay-2023-33937","CVE-2023-33937"],"modified":"2023-12-06T00:47:59.957284Z","published":"2023-05-24T15:30:27Z","database_specific":{"github_reviewed_at":"2023-05-24T18:04:15Z","nvd_published_at":"2023-05-24T13:15:09Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33937"},{"type":"PACKAGE","url":"https://github.com/liferay/liferay-portal"},{"type":"WEB","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33937"}],"affected":[{"package":{"name":"com.liferay.portal:release.portal.bom","ecosystem":"Maven","purl":"pkg:maven/com.liferay.portal/release.portal.bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.3.1"}]}],"versions":["7.1.0","7.1.1","7.1.2","7.1.3","7.1.3-1","7.2.0","7.2.1","7.2.1-1","7.3.0","7.3.0-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-v6m2-j92j-2h78/GHSA-v6m2-j92j-2h78.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}