Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via an invalid portletId. Remediation References CVE-2017-12645 Related Vulnerabilities WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.4.1) WordPress Plugin Leaflet Maps Marker Pro (Google Maps, OpenStreetMap, Bing Maps) Multiple Cross-Site Scripting Vulnerabilities (2.3) Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-23126) Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3727) WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.2) Severity Medium Classification CVE-2017-12645 CWE-707 Tags Missing Update Known Vulnerabilities