Server side cross-site scripting In com.liferay.commerce:com.liferay.commerce.catalog.web
Description
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects the Commerce module before 4.0.8 from Liferay Portal (7.3.5 through 7.4.2) and Liferay DXP 7.3 before update 8.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 4.0.8 | ||
maven | 7.3.10.u8 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.