Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a login name, password, or e-mail address. Remediation References CVE-2017-12646 Related Vulnerabilities Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874) WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Scripting (2.2.7) osTicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-15362) Joomla! Core 3.x.x Information Disclosure (3.6.0 - 3.9.12) Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24407) Severity Medium Classification CVE-2017-12646 CWE-707 Tags Missing Update Known Vulnerabilities