Description
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
Remediation
References
Related Vulnerabilities
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-10159)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2023-0401)
WordPress Plugin Highlight Search Terms Cross-Site Scripting (1.3)
Apache Tomcat Other Vulnerability (CVE-2007-3383)
Oracle Database Server CVE-2014-6547 Vulnerability (CVE-2014-6547)