Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the comliferayredirectwebinternalportletRedirectPortletdestinationURL parameter.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:liferay:dxp:7.3:-:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.3-NA"
}
]
}
]
}