Description
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2014-0098 Vulnerability (CVE-2014-0098)
Joomla Improper Input Validation Vulnerability (CVE-2018-11321)
Envoy Proxy Reachable Assertion Vulnerability (CVE-2024-32475)
WordPress Plugin Contact Form by BestWebSoft Cross-Site Scripting (3.51)
WordPress Plugin WordPress Leads Cross-Site Scripting (1.6.2)