Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-17868 - Vulnerability Database

Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-17868

Medium
Reference: CVE-2017-17868
Title: Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In Liferay Portal 6.1.0 the tags section has XSS via a Public Render Parameter (p_r_p) value as demonstrated by p_r_p_564233524_tag.