Description
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
Remediation
References
https://github.com/liferay/liferay-portal/commit/7e063aed70f947a92bb43a4471e0c4e650fe8f7f
Related Vulnerabilities
CVE-2021-25979 Vulnerability in npm package apostrophe
CVE-2022-2900 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-imap4
CVE-2021-28860 Vulnerability in npm package mixme
CVE-2017-7661 Vulnerability in maven package org.apache.cxf.fediz:fediz-jetty9