CVE-2007-6055: XSS
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6055?
CVE-2007-6055 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-6055?
To fix CVE-2007-6055, it is advised to upgrade Liferay Portal to version 4.1.2 or later.
What software is affected by CVE-2007-6055?
CVE-2007-6055 affects Liferay Portal versions 4.1.0 and 4.1.1.
What is the nature of CVE-2007-6055?
CVE-2007-6055 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts into the login parameter.
Can CVE-2007-6055 lead to user data compromise?
Yes, CVE-2007-6055 can lead to user data compromise by enabling attackers to execute arbitrary scripts in the context of the victim's browser.