Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2018-17785 Vulnerability in maven package cc.blynk.server.api.core:http-core
CVE-2020-14060 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash