Stored cross-site scripting in Liferay Enterprise Portal - #VU8560
Published: September 21, 2017
Liferay Enterprise Portal
Detailed vulnerability description
The vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Monitoring. A remote attacker can trick the victim to visit a page with XSS payload and execute arbitrary HTML and script code in victim’s browser in security context of the affected website.