Description
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
Remediation
References
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33942
Related Vulnerabilities
CVE-2020-2211 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci
CVE-2021-21605 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-24430 Vulnerability in maven package org.jenkins-ci.plugins:semantic-versioning-plugin
CVE-2017-1000106 Vulnerability in maven package io.jenkins.blueocean:blueocean-bitbucket-pipeline
CVE-2023-41037 Vulnerability in maven package org.webjars.npm:openpgp