Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a bookmark URL. Remediation References CVE-2017-12648 Related Vulnerabilities SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-36501) WordPress Plugin IWantOneButton 'updateAJAX.php' SQL Injection (3.0.1) WordPress Plugin EventCommerce WP Event Calendar Cross-Site Scripting (1.0) WordPress Plugin Slideshow Multiple Cross-Site Scripting Vulnerabilities (2.1.14) WordPress Plugin Banner Slider Cross-Site Scripting (1.0) Severity Medium Classification CVE-2017-12648 CWE-707 Tags Missing Update Known Vulnerabilities