Description
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Klaviyo Cross-Site Scripting (3.0.7)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9848)
WordPress Plugin Media Library Categories 'termid' Parameter SQL Injection (1.0.6)
Joomla! Core Cross-Site Scripting (1.6.0 - 3.8.8)
Atlassian Jira CVE-2019-20413 Vulnerability (CVE-2019-20413)