First published: Sat May 22 2004(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | <=2.1.1 | |
Liferay 7.4 GA | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2030 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2004-2030, upgrade Liferay Enterprise Portal to version 2.2.0 or later.
The risks include the potential for attackers to execute arbitrary scripts in the context of a user's browser.
CVE-2004-2030 affects Liferay Enterprise Portal versions prior to 2.2.0, specifically up to 2.1.1.
While the best practice is to upgrade, you may also implement input validation and sanitization to mitigate risks.