Description
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wp-Pro-Quiz Cross-Site Request Forgery (0.37)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4825)
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2019-3894)
WebLogic Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-11987)