Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2020-7693 Vulnerability in maven package org.webjars.npm:sockjs
CVE-2022-39243 Vulnerability in maven package com.zaxxer:nuprocess
CVE-2020-28270 Vulnerability in npm package object-hierarchy-access
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-27216 Vulnerability in maven package org.eclipse.jetty:jetty-webapp