Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0-ga1"
},
{
"introduced": "0"
},
{
"last_affected": "7.2.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "7.2.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "7.2.0-rc3"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16147.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0-alpha1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0-beta3"
}
]
}
]