Description
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
Remediation
References
Related Vulnerabilities
Joomla Credentials Management Errors Vulnerability (CVE-2016-9081)
WordPress Plugin Mongoose Page Cross-Site Scripting (1.8.3)
WordPress Plugin Booking Calendar-Appointment Booking-BookIt Security Bypass (2.3.7)
RubyGems Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1000075)