Description
Liferay Portal through v7.3.6 and Liferay DXP through v7.3 were discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Blog Entry function under the Blog module.
Remediation
References
Related Vulnerabilities
Ruby Other Vulnerability (CVE-2014-8090)
MySQL Improper Access Control Vulnerability (CVE-2016-8288)
Oracle JRE CVE-2023-22049 Vulnerability (CVE-2023-22049)
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-7187)
WordPress Plugin Gallery Plugin for WordPress-Envira Photo Gallery Cross-Site Scripting (1.8.3.2)