Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
| Software | From | Fixed in |
|---|---|---|
| liferay / liferay_portal | 7.3.5 | 7.4.2.x |
| liferay / dxp | 7.3 | 7.3.x |
| liferay / dxp | 7.3-update_1 | 7.3-update_1.x |
| liferay / dxp | 7.3-update_2 | 7.3-update_2.x |
| liferay / dxp | 7.3-update_3 | 7.3-update_3.x |
| liferay / dxp | 7.3-update_4 | 7.3-update_4.x |
| liferay / dxp | 7.3-update_5 | 7.3-update_5.x |
| liferay / dxp | 7.3-update_6 | 7.3-update_6.x |
| liferay / dxp | 7.3-update_7 | 7.3-update_7.x |