Server side cross-site scripting In com.liferay:com.liferay.sharing.web
Description
Liferay Portal and Liferay DXP Vulnerable to XSS via the Sharing Module A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification before 3.0.9 from Liferay Portal (7.2.1 through 7.4.2), and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.0.9 | ||
maven | 7.2.10.fp19, 7.3.10.u4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.