Description
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Remediation
References
Related Vulnerabilities
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2016-7137)
Joomla! Core 1.6.x Information Disclosure (1.6.0 - 1.6.3)
Oracle JRE CVE-2024-21145 Vulnerability (CVE-2024-21145)
WordPress Plugin Flat Preloader Cross-Site Scripting (1.5.4)
WordPress Plugin WP Gravity Forms Zendesk Cross-Site Scripting (1.0.7)