Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the comliferayblogswebportletBlogsAdminPortlettitle and comliferayblogswebportletBlogsAdminPortletsubtitle parameter.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-fix_pack_1"
},
{
"introduced": "7.3.2"
},
{
"last_affected": "7.3.6"
}
]
}