Description
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Redirection Cross-Site Request Forgery (3.6.2)
WordPress Plugin WP Maintenance Mode & Site Under Construction Cross-Site Request Forgery (1.8.2)
Plone CMS Improper Access Control Vulnerability (CVE-2015-7315)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-5252)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-5539)