Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a login name, password, or e-mail address. Remediation References CVE-2017-12646 Related Vulnerabilities Ruby on Rails Inefficient Regular Expression Complexity Vulnerability (CVE-2023-22795) phpMyAdmin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2008-4326) Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35131) TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7081) Django Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-9402) Severity Medium Classification CVE-2017-12646 CWE-707 Tags Missing Update Known Vulnerabilities