Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via an invalid portletId. Remediation References CVE-2017-12645 Related Vulnerabilities MODX Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20758) Moodle Improper Input Validation Vulnerability (CVE-2018-1137) WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.18) WordPress Plugin Answer My Question SQL Injection (1.3) Lighttpd Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2015-3200) Severity Medium Classification CVE-2017-12645 CWE-707 Tags Missing Update Known Vulnerabilities