Description
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Membership Cross-Site Scripting (3.5.6)
WordPress Plugin Advanced Custom Fields (ACF) Cross-Site Scripting (6.1.5)
WordPress 4.2.x Cross-Site Scripting Vulnerability (4.2 - 4.2.7)
WordPress Plugin WooCommerce Cross-Site Scripting (2.6.8)
WordPress Plugin WP Business Intelligence Lite SQL Injection (1.6.1)