Description
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
Remediation
References
Related Vulnerabilities
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2024-21140)
WordPress Plugin Chronoforms Cross-Site Request Forgery (7.0.9)
WordPress Plugin Gantry 5 Framework Cross-Site Scripting (5.4.8)
WordPress Plugin Zielke Specialized Catalog Arbitrary File Upload (3.0.7)