Description
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
Remediation
References
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33942
Related Vulnerabilities
CVE-2022-2053 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-cocoapods-plugin
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2020-6457 Vulnerability in npm package electron
CVE-2023-25158 Vulnerability in maven package org.geotools.jdbc:gt-jdbc-oracle