Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
axios Uncontrolled Resource Consumption Vulnerability (CVE-2021-3749)
Oracle Application Server Improper Authentication Vulnerability (CVE-2002-0563)
WordPress Plugin Live Chat-Live support Cross-Site Request Forgery (3.1.0)
PostgreSQL Untrusted Search Path Vulnerability (CVE-2020-14350)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-3011)