Description
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
Remediation
References
https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-70/-/asset_publisher/cjE0ourZXJZE/content/cst-7017-multiple-xss-vulnerabilities
https://issues.liferay.com/browse/LPS-72307
Related Vulnerabilities
CVE-2020-11620 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-29008 Vulnerability in npm package @sveltejs/kit
CVE-2022-42004 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-5432 Vulnerability in maven package org.webjars.npm:mqtt-packet
CVE-2023-25499 Vulnerability in maven package com.vaadin:vaadin