Description
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.
Remediation
References
Related Vulnerabilities
PHP Incorrect Conversion between Numeric Types Vulnerability (CVE-2018-5711)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3226)
Oracle Database Server Other Vulnerability (CVE-2006-5343)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2202)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.7.5)