Description
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
Remediation
References
Related Vulnerabilities
ATutor Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-43498)
MySQL CVE-2020-2898 Vulnerability (CVE-2020-2898)
WordPress Plugin WP Database Backup Cross-Site Request Forgery (5.1.2)
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Cross-Site Scripting (3.2.9)
WordPress Plugin aoringo TAG upper Cross-Site Scripting (0.1.6)