Description
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-34798)
XWiki Improper Access Control Vulnerability (CVE-2023-29513)
MongoDb Improper Input Validation Vulnerability (CVE-2012-6619)
WordPress Plugin Category and Page Icons Cross-Site Scripting (0.9.2)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-4558)