Description
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2020-2884 Vulnerability (CVE-2020-2884)
WordPress Plugin Easy Appointments Cross-Site Scripting (1.11.7)
WordPress Plugin Contact Form 7 Datepicker Cross-Site Scripting (2.6.0)
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.2.2)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease SQL Injection (4.6.1)