#VU8548 Improper input validation in Liferay Enterprise Portal
Published: September 21, 2017
Liferay Enterprise Portal
Liferay
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient input sanitization when creating or editing Wiki pages. A remote authenticated attacker with permissions to create or edit a Wiki page can cause a denial of service (DoS) in the portal via crafted form parameters.
Remediation
https://sourceforge.net/projects/liferay-patches/files/7.0.3%20GA4/
https://github.com/community-security-team/liferay-portal/compare/7.0.3-ga4...7.0.3-CST-7029.patch