Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_name parameter.
Software | From | Fixed in |
---|---|---|
liferay / liferay_portal | 7.3.4 | 7.3.4.x |
liferay / dxp | 7.3 | 7.3.x |
liferay / liferay_portal | 7.3.5 | 7.3.5.x |
liferay / digital_experience_platform | 7.2 | 7.2.x |
liferay / digital_experience_platform | 7.2-fix_pack_1 | 7.2-fix_pack_1.x |
liferay / digital_experience_platform | 7.2-fix_pack_2 | 7.2-fix_pack_2.x |
liferay / digital_experience_platform | 7.2-fix_pack_3 | 7.2-fix_pack_3.x |
liferay / digital_experience_platform | 7.2-fix_pack_5 | 7.2-fix_pack_5.x |
liferay / digital_experience_platform | 7.2-fix_pack_4 | 7.2-fix_pack_4.x |
liferay / digital_experience_platform | 7.2-fix_pack_6 | 7.2-fix_pack_6.x |
liferay / digital_experience_platform | 7.2-fix_pack_7 | 7.2-fix_pack_7.x |
liferay / digital_experience_platform | 7.2-fix_pack_8 | 7.2-fix_pack_8.x |
liferay / digital_experience_platform | 7.2-fix_pack_9 | 7.2-fix_pack_9.x |
liferay / digital_experience_platform | 7.2-fix_pack_10 | 7.2-fix_pack_10.x |