Description
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21412 Vulnerability (CVE-2022-21412)
WordPress Plugin WP Super Cache Multiple Vulnerabilities (1.4.4)
Oracle Application Server Other Vulnerability (CVE-2002-0569)
Magento Improper Input Validation Vulnerability (CVE-2019-7898)
WordPress Plugin WP Coder-add custom html, css and js code Cross-Site Request Forgery (2.5.2)