Description
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Information Disclosure (3.7.0 - 3.8.1)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.14)
Jenkins Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-43497)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1041)
WordPress Plugin Pagination by BestWebSoft Cross-Site Scripting (1.0.6)