Description
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Cross-Site Scripting (2.4.8)
Apache HTTP Server Insertion of Sensitive Information into Log File Vulnerability (CVE-2001-1556)
WordPress Plugin Form Builder Cross-Site Scripting (1.2.0)
SharePoint Improper Certificate Validation Vulnerability (CVE-2019-1006)
WordPress Plugin bodi0`s Easy cache Cross-Site Scripting (0.8)