Reflected cross-site scripting (XSS) In com.liferay:com.liferay.frontend.taglib.clay

Description

Liferay Portal vulnerable to cross-site scripting (XSS) via the keywords parameter Liferay Portal v7.4.1 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the keywords parameter under the Frontend Taglib module before 7.1.15.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions