Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
WordPress Plugin OneLogin SAML SSO Unspecified Vulnerability (2.1.8)
Next.js Uncontrolled Resource Consumption Vulnerability (CVE-2024-39693)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-19499)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-4476)