Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a login name, password, or e-mail address. Remediation References CVE-2017-12646 Related Vulnerabilities Oracle JRE CVE-2013-2455 Vulnerability (CVE-2013-2455) MediaWiki CVE-2023-29141 Vulnerability (CVE-2023-29141) Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4790) Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000816) Liferay DXP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606) Severity Medium Classification CVE-2017-12646 CWE-707 Tags Missing Update Known Vulnerabilities