Description
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
Remediation
References
Related Vulnerabilities
Telerik Web UI Insufficiently Protected Credentials Vulnerability (CVE-2017-9248)
Roundcube Improper Input Validation Vulnerability (CVE-2011-1491)
WordPress Plugin PickPlugins Product Slider for WooCommerce Unspecified Vulnerability (1.13.23)
Oracle Database Server CVE-2011-3512 Vulnerability (CVE-2011-3512)