Description
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2019-1035 Vulnerability (CVE-2019-1035)
Oracle Database Server CVE-2014-4289 Vulnerability (CVE-2014-4289)
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.17)
WordPress Plugin Login by Auth0 Cross-Site Scripting (3.11.2)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3433)