CVE-2023-47797: Liferay Portal

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.

Affected products

  • Liferay Liferay Portal: from 7.4.3.94, up to and including 7.4.3.95

Published 2023-11-17. Last modified 2026-06-17.