Liferay Portal and Liferay DXP allows arbitrary injection via form field
Moderate severity
GitHub Reviewed
Published
Apr 16, 2022
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Apr 15, 2022
Published to the GitHub Advisory Database
Apr 16, 2022
Reviewed
Jul 14, 2025
Last updated
Jul 14, 2025
Multiple cross-site scripting (XSS) vulnerabilities in Dynamic Data Mapping Form Field Type before 6.0.11 from Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
References