CVE-2011-1570: XSS
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1570?
CVE-2011-1570 has been categorized as a moderate severity Cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-1570?
To fix CVE-2011-1570, upgrade Liferay Portal Community Edition to version 6.0.6 GA or later.
Who is affected by CVE-2011-1570?
Remote authenticated users of Liferay Portal Community Edition 6.x prior to 6.0.6 GA are affected by CVE-2011-1570.
What type of vulnerability is CVE-2011-1570?
CVE-2011-1570 is a Cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
What versions of Liferay Portal are vulnerable to CVE-2011-1570?
Liferay Portal Community Edition versions 6.0.0 to 6.0.5 are vulnerable to CVE-2011-1570.