Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
Apache HTTP Server CVE-2004-0751 Vulnerability (CVE-2004-0751)
Plone CMS Improper Privilege Management Vulnerability (CVE-2020-7941)
MediaWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2020-35475)
PHP Out-of-bounds Read Vulnerability (CVE-2019-11035)
WordPress Plugin WordPress Landing Pages Multiple Vulnerabilities (1.8.4)