Description
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Remediation
References
Related Vulnerabilities
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-37911)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-2041)
Moodle CVE-2019-3852 Vulnerability (CVE-2019-3852)
Apache HTTP Server Other Vulnerability (CVE-2007-1742)
WordPress Plugin LearnPress-WordPress LMS Cross-Site Scripting (4.1.6.5)