Cross-site scripting in Liferay Enterprise Portal - #VU8557
Published: September 21, 2017
Liferay Enterprise Portal
Detailed vulnerability description
The vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the <aui:form> tag. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of the affected website.