Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-17868 - Vulnerability Database
Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-17868
Medium
Reference:
CVE-2017-17868
Title:
Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Liferay Portal 6.1.0 the tags section has XSS via a Public Render Parameter (p_r_p) value as demonstrated by p_r_p_564233524_tag.