Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-4724)
WordPress Plugin WP Social Feed Gallery Unspecified Vulnerability (2.1.1)
OpenSSL Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-2650)
WordPress Plugin Simple Video Embedder Cross-Site Scripting (2.2)