First published: Sat May 07 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | =5.1.2 | |
Liferay 7.4 GA | =5.2.3 | |
Liferay 7.4 GA | =6.0.5 | |
Liferay 7.4 GA | =5.0.1-rc | |
Liferay 7.4 GA | =6.0.2 | |
Liferay 7.4 GA | =5.2.1 | |
Liferay 7.4 GA | =5.1.0 | |
Liferay 7.4 GA | =5.2.2 | |
Liferay 7.4 GA | =5.2.0 | |
Liferay 7.4 GA | =6.0.4 | |
Liferay 7.4 GA | =5.0.0-rc | |
Liferay 7.4 GA | =5.1.1 | |
Liferay 7.4 GA | =6.0.1 | |
Liferay 7.4 GA | =6.0.3 | |
Liferay 7.4 GA | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1504 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-1504, upgrade Liferay Portal Community Edition to version 6.0.6 GA or later.
CVE-2011-1504 affects remote authenticated users of Liferay Portal Community Edition versions 5.x and 6.x prior to 6.0.6 GA.
CVE-2011-1504 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web script or HTML.
Exploiting CVE-2011-1504 may allow attackers to execute malicious scripts in the context of a user's session, potentially compromising sensitive information.