Description
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2008-3660)
WordPress Plugin Relevanssi-A Better Search Cross-Site Scripting (3.3.7.1)
PHP Out-of-bounds Write Vulnerability (CVE-2020-7065)
WordPress Plugin Highlight Cross-Site Scripting (0.9.2)
WordPress Plugin GD Star Rating 'export.php' Security Bypass (1.9.18)