Description
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
Remediation
References
Related Vulnerabilities
WordPress Plugin ChimpMate-WordPress MailChimp Assistant Local File Inclusion (1.3.2)
WordPress Plugin Testimonial Slider Multiple Cross-Site Scripting Vulnerabilities (1.2.5)
MySQL CVE-2017-3452 Vulnerability (CVE-2017-3452)
WordPress Ultimate Member Plugin CVE-2020-36170 Vulnerability (CVE-2020-36170)