Description
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
Remediation
References
Related Vulnerabilities
WordPress Plugin ExS Widgets Local File Inclusion (0.3.1)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-29450)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7861)
WordPress Plugin Event Calendar WD-Responsive Event Calendar Cross-Site Scripting (1.1.42)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371)