Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-12649)
Description
XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a crafted title or summary that is mishandled in the Web Content Display.