Description
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Remediation
References
Related Vulnerabilities
WordPress Plugin Random image gallery with pretty photo zoom Cross-Site Scripting (7.4)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Privilege Escalation (3.3.1)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2019-4156)
WordPress 2.6.1 Lost Password SQL Column Truncation Unauthorized Access Vulnerability (0.71 - 2.6.1)