Description
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
Remediation
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0057)
WordPress 4.2.x Arbitrary File Deletion Vulnerability (4.2 - 4.2.20)
WordPress Plugin WordPress Books Gallery Unspecified Vulnerability (4.4.1)
WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple HTML Injection Vulnerabilities (1.9.0)
WordPress Plugin Elementor Website Builder Multiple Vulnerabilities (3.16.4)