Server side cross-site scripting In com.liferay.commerce:com.liferay.commerce.catalog.web

Description

Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects the Commerce module before 4.0.8 from Liferay Portal (7.3.5 through 7.4.2) and Liferay DXP 7.3 before update 8.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions