Description
Liferay Portal v7.3.2 and below and Liferay DXP v7.0 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the script console under the Server module.
Remediation
References
Related Vulnerabilities
Claroline Other Vulnerability (CVE-2006-1595)
Jetty CVE-2020-27218 Vulnerability (CVE-2020-27218)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2006-0200)
WordPress Plugin Job Manager Multiple Cross-Site Scripting Vulnerabilities (0.7.18)
WordPress Plugin Category List Portfolio Page TimThumb Arbitrary File Upload (1.2.3)