Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2024-30044)
Next.js Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2022-36046)
PHP Out-of-bounds Read Vulnerability (CVE-2022-31630)
WordPress Plugin Theme Test Drive Multiple Vulnerabilities (2.9)
Joomla! Core 3.x.x Multiple Cross-Site Request Forgery Vulnerabilities (3.2.0 - 3.9.15)