Description
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Remediation
References
Related Vulnerabilities
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9276)
Apache Traffic Server Integer Overflow or Wraparound Vulnerability (CVE-2018-9481)
WordPress 4.5.x Possible SQL Injection Vulnerability (4.5 - 4.5.10)
WordPress Plugin MasterStudy LMS-for Online Courses and Education SQL Injection (3.2.5)
WordPress Plugin Staff Directory:Company Directory Cross-Site Request Forgery (3.6)