Cross-site scripting in Liferay Enterprise Portal - #VU8549

 

Cross-site scripting in Liferay Enterprise Portal - #VU8549

Published: September 21, 2017


Vulnerability identifier: #VU8549
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability exists due to insufficient input sanitization in various web application components. A remote attacker can trick the victim into visiting a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of the affected website.


Affected software

Liferay Enterprise Portal

Remediation



External References

Related Security Bulletins