Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-widget
CVE-2023-1283 Vulnerability in npm package @builder.io/qwik
CVE-2017-16158 Vulnerability in npm package dcserver
CVE-2022-41918 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2021-3597 Vulnerability in maven package io.undertow:undertow-core