legacy-knowledge-base
公開されました Jun. 30, 2025

保存されたXSS脆弱性のログメッセージ

written-by

Peter Schwarcz

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

問題

  • 私たちの環境で以下の脆弱性が悪用されたかどうかを確認するために、ログファイルから検索する文字列があるかどうか知りたいのですが。
    • LSV-1237 / CVE-2023-42628
    • LSV-1236 / CVE-2023-42627
    • LSV-1194 / CVE-2023-44310

環境

  • Liferay DXP 7.4

解像度

  • 言及されている脆弱性はすべてXSS(クロスサイトスクリプティング)の脆弱性で、パッチが適用されていない特定のLiferayバージョンで悪用される可能性があります。
  • これらの3つはすべて、 stored XSS脆弱性であり、コンテンツ(通常は悪意のあるスクリプト)がデータベースに保存されることを意味する。 このようなエクスプロイトの影響を受けた可能性がある場合は、ログファイルではなく、影響を受けたデータベーステーブルの不正なデータ/スクリプトを確認することをお勧めします。

追加情報

did-this-article-resolve-your-issue

legacy-knowledge-base