Description
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
Remediation
References
https://issues.liferay.com/browse/LPS-72307
https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-70/-/asset_publisher/cjE0ourZXJZE/content/cst-7017-multiple-xss-vulnerabilities
Related Vulnerabilities
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2022-27202 Vulnerability in maven package org.jenkins-ci.plugins:extended-choice-parameter
CVE-2021-3536 Vulnerability in maven package org.wildfly:wildfly-parent
CVE-2020-28496 Vulnerability in npm package three
CVE-2023-43795 Vulnerability in maven package org.geoserver.extension:gs-wps-core