A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-sp1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-sp2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-sp3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_4"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_5"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_6"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_7"
},
{
"introduced": "7.3.0"
},
{
"last_affected": "7.4.0"
}
]
}