Liferay Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2020-13445
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92 7.1 before fix pack 18 and 7.2 before fix pack 6 the template API does not restrict user access to sensitive objects which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.