Description
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
Remediation
References
Related Vulnerabilities
Dotclear Improper Access Control Vulnerability (CVE-2015-8832)
Artifactory Improper Privilege Management Vulnerability (CVE-2022-0668)
Piwigo Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2025-62406)
WordPress Plugin Timetable and Event Schedule by MotoPress Cross-Site Request Forgery (2.4.1)
WordPress Plugin Quick Event Manager Security Bypass (9.2.16)