CVE-2023-37940

📊 4.8 MEDIUM0.1%🎯 0 exploits
📅 Published Dec 17, 2024
📋 Status: Analyzed

Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field.

🎯 Affected Products & Systems

121 product configurations affected

Filter by type:
📱
Application
Vulnerable
Version: ≥ 7.0.0 ∧ < 7.4.3.88
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Vulnerable
Version: ≥ 7.0 ∧ < 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update15:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update16:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update17:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update18:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update19:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update20:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update21:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update22:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update23:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update24:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update25:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update26:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update27:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update28:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update29:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update4:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update5:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update6:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update7:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update8:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update9:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:*
121 productsscroll for more
Metrics
4.8 MEDIUMCVSS v3.1[email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
HIGH
User Interaction:
REQUIRED
Confidentiality:
LOW
Integrity:
LOW
Availability:
NONE
Scope:
CHANGED

🔍 Technical Details

Analysis Status
Analyzed
CVSS Details
4.8 (MEDIUM)v3.1
EPSS Details
0.1% (Minimal)22.7th percentile
Last updated: Oct 30, 2025
Exploitation probability within 30 days
Published Date
Dec 17, 2024 (10 months ago)
Last Modified
Jan 28, 2025 (9 months ago)
Security Weaknesses1
References2