Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2021-24104 Vulnerability (CVE-2021-24104)
OpenSSL Other Vulnerability (CVE-2014-0198)
WordPress Plugin BulletProof Security Multiple Cross-Site Scripting Vulnerabilities (.53.2)
MySQL CVE-2022-21595 Vulnerability (CVE-2022-21595)
WordPress Plugin Realty by BestWebSoft Cross-Site Scripting (1.0.9)