Total vulnerabilities in the database
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
Software | From | Fixed in |
---|---|---|
liferay / dxp | 7.3 | 7.3.x |
liferay / liferay_portal | 7.3.0 | 7.4.0.x |
liferay / dxp | 7.3-update_1 | 7.3-update_1.x |
liferay / dxp | 7.3-update_2 | 7.3-update_2.x |
liferay / dxp | 7.3-update_3 | 7.3-update_3.x |
liferay / dxp | 7.3-update_4 | 7.3-update_4.x |
liferay / dxp | 7.3-update_5 | 7.3-update_5.x |
liferay / dxp | 7.3-update_6 | 7.3-update_6.x |
liferay / dxp | 7.3-update_7 | 7.3-update_7.x |
liferay / dxp | 7.3-update_8 | 7.3-update_8.x |
liferay / dxp | 7.3-sp1 | 7.3-sp1.x |
liferay / dxp | 7.3-sp2 | 7.3-sp2.x |
liferay / dxp | 7.3-sp3 | 7.3-sp3.x |