Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Assignee
EE SupportEE SupportReporter
Samuel KongSamuel Kong(Deactivated)Priority
Low
Details
Details
Assignee
EE Support
EE SupportReporter
Samuel Kong
Samuel Kong(Deactivated)Priority
Zendesk Support
Zendesk Support
Zendesk Support
Created September 22, 2022 at 3:29 AM
Updated October 18, 2022 at 7:07 PM
Resolved October 18, 2022 at 7:07 PM
Cross-site scripting (XSS) vulnerability in the Commerce module's edit catalog page in Liferay DXP 7.3 before update 8 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_commerce_catalog_web_internal_portlet_CommerceCatalogsPortlet_externalReferenceCode parameter.