Description
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2600)
WordPress Plugin WP Maintenance Mode Remote Code Execution (2.0.6)
WordPress Plugin Simple Banner Cross-Site Scripting (2.11.0)
Oracle JRE CVE-2012-3136 Vulnerability (CVE-2012-3136)
Oracle Application Server CVE-2009-0974 Vulnerability (CVE-2009-0974)