XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
{
"github_reviewed": true,
"github_reviewed_at": "2025-08-08T20:36:41Z",
"severity": "MODERATE",
"nvd_published_at": "2017-08-07T16:29:00Z",
"cwe_ids": [
"CWE-79"
]
}