Description XSS exists in Liferay Portal before 7.0 CE GA4(7.0.3) via a login name, password, or e-mail address. Remediation References CVE-2017-12646 Related Vulnerabilities WordPress Plugin SP Rental Manager SQL Injection (1.5.3) WordPress Plugin Portfolio by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (2.27) WordPress Plugin Copy or Move Comments Multiple Vulnerabilities (1.0.0) ReviveAdserver Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-7373) MongoDb Improper Authentication Vulnerability (CVE-2014-8180) Severity Medium Classification CVE-2017-12646 CWE-707 Tags Missing Update Known Vulnerabilities