Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a login name, password, or e-mail address. Remediation References CVE-2017-12646 Related Vulnerabilities WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.17) MediaWiki Use of Hard-coded Credentials Vulnerability (CVE-2012-4381) Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-2938) WordPress Plugin Relevanssi Premium-A Better Search Cross-Site Scripting (1.14.8) WordPress Plugin Reusable Blocks Extended Cross-Site Request Forgery (0.9) Severity Medium Classification CVE-2017-12646 CWE-707 Tags Missing Update Known Vulnerabilities