Description
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.9.7)
WordPress Plugin Jigoshop Information Disclosure (1.17.9)
WordPress Other Vulnerability (CVE-2004-1559)
Oracle JRE CVE-2018-2815 Vulnerability (CVE-2018-2815)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2043)