A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
2022-10-13T13:15:10.043
2025-05-15T16:15:26.183
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | dxp | 7.3 | Yes |
Application | liferay | liferay_portal | ≤ 7.4.0 | Yes |