Description
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
Remediation
References
Related Vulnerabilities
PHP Resource Management Errors Vulnerability (CVE-2006-1991)
WordPress Plugin Insert Pages Directory Traversal (3.2.3)
e107 Other Vulnerability (CVE-2010-0996)
WordPress Plugin Mail On Update Cross-Site Request Forgery (5.1.0)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-5539)