Description
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
Remediation
References
Related Vulnerabilities
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2015-3416)
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2025-29088)
WordPress 'swfupload.swf' Cross-Site Scripting Vulnerability (2.5 - 3.3.1)
Oracle JRE CVE-2013-2415 Vulnerability (CVE-2013-2415)
WordPress Plugin Disable Comments Cross-Site Request Forgery (1.0.3)