Description
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call
Remediation
References
http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3
Related Vulnerabilities
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp
CVE-2022-34208 Vulnerability in maven package org.jenkins-ci.plugins:beaker-builder
CVE-2022-31127 Vulnerability in npm package next-auth
CVE-2017-12612 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2020-4070 Vulnerability in maven package org.w3c.css:css-validator