CVE-2016-3670 | Liferay up to 7.0.0 Profile Search users.jsp FirstName cross site scripting (Exploit 137279 / EDB-39880)
A vulnerability classified as problematic has been found in Liferay up to 7.0.0. This affects an unknown part of the file users.jsp of the component Profile Search. The manipulation of the argument FirstName leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2016-3670. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.