Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.
Software | From | Fixed in |
---|---|---|
liferay / liferay_portal | 7.2.1 | 7.3.5 |
liferay / digital_experience_platform | 7.2 | 7.2.x |
liferay / digital_experience_platform | 7.2-fix_pack_1 | 7.2-fix_pack_1.x |
liferay / digital_experience_platform | 7.2-fix_pack_2 | 7.2-fix_pack_2.x |
liferay / digital_experience_platform | 7.2-fix_pack_3 | 7.2-fix_pack_3.x |
liferay / digital_experience_platform | 7.2-fix_pack_5 | 7.2-fix_pack_5.x |
liferay / digital_experience_platform | 7.2-fix_pack_4 | 7.2-fix_pack_4.x |
liferay / digital_experience_platform | 7.2-fix_pack_6 | 7.2-fix_pack_6.x |
liferay / digital_experience_platform | 7.2-fix_pack_7 | 7.2-fix_pack_7.x |
liferay / digital_experience_platform | 7.2-fix_pack_8 | 7.2-fix_pack_8.x |