Description
Liferay Portal v7.3.6 and below and Liferay DXP v7.3 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin About Author Cross-Site Scripting (1.3.9)
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21357)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0245)
WordPress Plugin Magic Fields 2 Unspecified Vulnerability (2.3.2.2)
PostgreSQL Incorrect Authorization Vulnerability (CVE-2021-20229)