Description
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
Remediation
References
Related Vulnerabilities
WordPress 4.0.x Denial of Service Vulnerability (4.0 - 4.0.22)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9414)
WordPress Plugin Eshop Magic Arbitrary File Disclosure (0.1)
Perl Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2827)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-13401)