Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2023-5571 Vulnerability in npm package @vrite/sdk
CVE-2017-1000043 Vulnerability in maven package org.webjars.npm:mapbox.js
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2023-26149 Vulnerability in npm package quill-mention
CVE-2020-17533 Vulnerability in maven package org.apache.accumulo:accumulo-core