Description
Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.
Remediation
References
Related Vulnerabilities
Moodle Other Vulnerability (CVE-2005-3648)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.18)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3370)
Magento CVE-2019-8123 Vulnerability (CVE-2019-8123)
WordPress Plugin Mikiurl WordPress Eklentisi Cross-Site Request Forgery (2.0)