Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-33326 - Vulnerability Database

Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-33326

Medium
Reference: CVE-2021-33326
Title: Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier and Liferay DXP 7.0 before fix pack 96 7.1 before fix pack 20 and 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.