Description
Liferay Portal v7.3.2 and below and Liferay DXP v7.0 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the script console under the Server module.
Remediation
References
Related Vulnerabilities
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0762)
Moodle Credentials Management Errors Vulnerability (CVE-2014-7845)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-1810)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2021-4183)