Description
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2017-10274 Vulnerability (CVE-2017-10274)
WordPress Plugin Custom Banners Cross-Site Scripting (1.2.2.2)
PHP Numeric Errors Vulnerability (CVE-2015-4021)
WordPress Plugin 360 Product Viewer Cross-Site Scripting (2.5.1)
Oracle Database Server CVE-2015-4740 Vulnerability (CVE-2015-4740)