Reflected cross-site scripting (XSS) In com.liferay.portal:release.dxp.bom

Description

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-5DY5H – Vulnerability | Fluid Attacks Database