Description
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Remediation
References
Related Vulnerabilities
Apache error log escape sequence injection vulnerability
WordPress Plugin Chained Quiz Cross-Site Scripting (1.2.7)
Oracle Application Server Other Vulnerability (CVE-2002-0566)
WordPress Plugin Random Banner Cross-Site Scripting (4.1.4)
WebLogic Download of Code Without Integrity Check Vulnerability (CVE-2020-5398)