Description
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
Remediation
References
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47797
Related Vulnerabilities
CVE-2011-2092 Vulnerability in maven package com.adobe.blazeds:blazeds-core
CVE-2021-21612 Vulnerability in maven package de.tracetronic.jenkins.plugins:ecutest
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc8
CVE-2017-4991 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2023-27987 Vulnerability in maven package org.apache.linkis:linkis-computation-client