Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.liferay:com.liferay.object.web(Maven) | 0 | 1.0.99 | N/A |
CVSS Metrics