Description
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
Remediation
References
Related Vulnerabilities
WordPress Plugin PowerPack Lite for Beaver Builder Cross-Site Scripting (1.3.0.4)
WordPress Plugin Symbiostock-Sell Photos Online For Free! Arbitrary File Upload (6.0.0)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2009-1387)
Jboss EAP Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-10212)