CVE-2007-6173: XSS
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress parameter in a Send New Password action, a different vector than CVE-2007-6055. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6173?
CVE-2007-6173 is considered a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2007-6173?
To fix CVE-2007-6173, users should upgrade to a patched version of Liferay Enterprise Portal that is not affected by this vulnerability.
What software is affected by CVE-2007-6173?
CVE-2007-6173 specifically affects Liferay Enterprise Portal version 4.3.1.
Can CVE-2007-6173 be exploited by unauthenticated users?
Yes, CVE-2007-6173 can be exploited by unauthenticated remote attackers through the emailAddress parameter.
What type of vulnerability is CVE-2007-6173?
CVE-2007-6173 is a Cross-site scripting (XSS) vulnerability.