#VU8549 Cross-site scripting in Liferay Enterprise Portal
Published: September 21, 2017
Liferay Enterprise Portal
Liferay
Description
The vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability exists due to insufficient input sanitization in various web application components. A remote attacker can trick the victim into visiting a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of the affected website.
Remediation
https://sourceforge.net/projects/liferay-patches/files/7.0.3%20GA4/
https://github.com/community-security-team/liferay-portal/compare/7.0.3-ga4...7.0.3-CST-7030.patch