A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-sp1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-sp2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-sp3"
}
]
}