Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
WordPress Plugin User Role by BestWebSoft Cross-Site Scripting (1.4.1)
WordPress Plugin PropertyHive Cross-Site Scripting (1.4.14)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20401)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0067)
IBM RTC Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2020-4544)