Description
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)
Collabtive Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-5285)
WordPress Plugin Aviary Image Editor Add-on For Gravity Forms Arbitrary File Upload (3.0)
MySQL CVE-2013-5786 Vulnerability (CVE-2013-5786)
WordPress Plugin BCS BatchLine Book Importer Security Bypass (1.5.7)