Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
https://cxsecurity.com/issue/WLB-2017120169
Related Vulnerabilities
CVE-2021-37694 Vulnerability in npm package @asyncapi/java-spring-cloud-stream-template
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-23358 Vulnerability in maven package org.webjars.bower:underscore
CVE-2019-5484 Vulnerability in maven package org.webjars.npm:bower
CVE-2020-26870 Vulnerability in maven package org.webjars.bower:dompurify