Cross-site scripting in Liferay Enterprise Portal - #VU8549
Published: September 21, 2017
Liferay Enterprise Portal
Detailed vulnerability description
The vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability exists due to insufficient input sanitization in various web application components. A remote attacker can trick the victim into visiting a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of the affected website.
Remediation
https://sourceforge.net/projects/liferay-patches/files/7.0.3%20GA4/
https://github.com/community-security-team/liferay-portal/compare/7.0.3-ga4...7.0.3-CST-7030.patch