Description
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1) Announcements, or (2) Alerts.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-0520 Vulnerability (CVE-2012-0520)
Oracle Application Server Other Vulnerability (CVE-2006-0552)
WordPress Plugin Bad Behavior Multiple Vulnerabilities (2.2.18)
WordPress Plugin Image Photo Gallery Final Tiles Grid Cross-Site Scripting (3.4.18)
Magento Violation of Secure Design Principles Vulnerability (CVE-2021-28583)