Liferay Enterprise Portal version 4.3.1 suffers from cross site scripting vulnerabilities.
986158a74be87e3ba5f50ed3a1b3c2e834d1089cb1e5ba2389926537b234b0b8
Vendor Site: Liferay.net
Version affected: Liferay Enterprise Portal 4.3.1
Demo:http://www.liferay.net/c/portal/login?tabs1=forgot-password
Class: Input Validation Error
Overview: Liferay fails to sufficiently sanitize user-supplied input data in "email address" text box by pressing the "Send New Password" button.
Examples:
1."><script>alert('xss')</script>
2.<html><b>XSS</b></font></html>
3."><iframe>
Discovered by: Joshua Morin