Description
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
Remediation
References
Related Vulnerabilities
WordPress Plugin PickPlugins Product Slider for WooCommerce Unspecified Vulnerability (1.13.23)
WordPress Plugin WordPress Facebook SQL Injection (1.0.8)
MySQL CVE-2016-5626 Vulnerability (CVE-2016-5626)
Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965)
Oracle Database Server CVE-2012-3151 Vulnerability (CVE-2012-3151)