Description
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
Remediation
References
https://github.com/liferay/liferay-portal/commit/7e063aed70f947a92bb43a4471e0c4e650fe8f7f
Related Vulnerabilities
CVE-2015-9286 Vulnerability in npm package nodebb
CVE-2016-8738 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-21165 Vulnerability in npm package electron
CVE-2021-33609 Vulnerability in maven package com.vaadin:vaadin-server
CVE-2021-27515 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse