Server side cross-site scripting In com.liferay:com.liferay.object.web

Description

Liferay Portal Vulnerable to XSS in the Object Module Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Object Web before 1.0.99 from Liferay Portal (7.4.3.4 through 7.4.3.36) allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's Label text field.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-R2GDO – Vulnerability | Fluid Attacks Database