CST-7224 Stored XSS with user name in Document & Media file info panel

Description

Stored cross-site scripting (XSS) vulnerability in the Document Library module in Liferay Portal 7.1.0 through 7.2.1 allows remote attackers to inject arbitrary web script or HTML via the user's name.

Severity

Severity 2

Fixed Version(s)

Publication date: Mon, 31 Aug 2020 17:00:00 +0000