CVE-2023-47798: Liferay Digital Experience Platform

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Affected products

  • Liferay Digital Experience Platform: before 7.2 (fixed in 7.2); version 7.2 only
  • Liferay Liferay Portal: from 7.2.0, before 7.3.0 (fixed in 7.3.0)

Published 2024-02-08. Last modified 2026-06-17.