Description
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
Remediation
References
Related Vulnerabilities
Lighttpd Resource Management Errors Vulnerability (CVE-2008-0983)
Drupal Core 4.6.x Denial of Service (4.6.0 - 4.6.10)
WordPress Plugin Import any XML or CSV File to WordPress Pro Arbitrary File Upload (4.1.0)
WordPress Plugin Generate PDF using Contact Form 7 Cross-Site Scripting (3.5)
WordPress Plugin AdRotate-Ad manager & AdSense Ads 'adrotate-out.php' SQL Injection (3.6.6)