Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-12649 - Vulnerability Database
            
		
	
    
                    Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-12649
            
    
        
								Medium
					
					        
        
            Reference:
            
                                CVE-2017-12649
            
        
                    
        
        
            Title:
            Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
        
        
            Overview:
            XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a crafted title or summary that is mishandled in the Web Content Display.