Liferay Portal Public Render Parameter Cross-Site Scripting Vulnerability
Description
(:A cross-site scripting was reported in Liferay Portal.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability stems from missing user-input validation on Public Render Parameter (p_r_p) parameter value.::A proof of concept is available.)