Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via an invalid portletId. Remediation References CVE-2017-12645 Related Vulnerabilities MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-35478) IBM WebSEAL CVE-2019-4135 Vulnerability (CVE-2019-4135) Django Improper Validation of Specified Quantity in Input Vulnerability (CVE-2023-41164) WordPress Plugin BookX Local File Inclusion (1.7) Plone CMS CVE-2011-0720 Vulnerability (CVE-2011-0720) Severity Medium Classification CVE-2017-12645 CWE-707 Tags Missing Update Known Vulnerabilities