Description
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
Remediation
References
Related Vulnerabilities
Drupal Improper Authentication Vulnerability (CVE-2019-10911)
Oracle Database Server CVE-2006-5334 Vulnerability (CVE-2006-5334)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-1443)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.5.4)
Liferay Portal Improper Certificate Validation Vulnerability (CVE-2022-42131)