Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
{
"versions": [
{
"introduced": "7.3.5"
},
{
"last_affected": "7.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_4"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_5"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_6"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_7"
}
]
}