Description
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
Remediation
References
https://github.com/liferay/liferay-portal/commit/7e063aed70f947a92bb43a4471e0c4e650fe8f7f
Related Vulnerabilities
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2019-3772 Vulnerability in maven package org.springframework.integration:spring-integration-ws
CVE-2017-16007 Vulnerability in npm package node-jose
CVE-2023-45278 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2017-7661 Vulnerability in maven package org.apache.cxf.fediz:fediz-spring2