Description
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gravity Forms Constant Contact Cross-Site Scripting (1.0.5)
WordPress Plugin WP Fastest Cache Directory Traversal (0.8.9.5)
WordPress Improper Input Validation Vulnerability (CVE-2014-9038)
WordPress Plugin OneLogin SAML SSO Security Bypass (2.2.0)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2183)