Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2023-31717 Vulnerability in npm package @frangoteam/fuxa
CVE-2020-7656 Vulnerability in maven package org.webjars:jquery
CVE-2022-24429 Vulnerability in npm package convert-svg-core
CVE-2021-26541 Vulnerability in npm package gitlog
CVE-2023-39156 Vulnerability in maven package org.jenkins-ci.plugins:bazaar