Liferay Cross-site Scritping Vulnerability Fixed by 7.0.0 CE RC1
Description
(:A stored cross-site scripting vulnerability was reported in Liferay.:A remote attacker could exploit via a specially crafted payload on the "FirstName" field, in order to execute arbitrary JavaScript code.::This vulnerability is located in the "Profile Search" feature via "User -> My Profile -> Search" and stems from an improper validation of user-supplied input.::A proof of concept is available.)