First published: Sat May 07 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | >=6.0.0<=6.0.5 | |
Microsoft Windows 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1570 has been categorized as a moderate severity Cross-site scripting (XSS) vulnerability.
To fix CVE-2011-1570, upgrade Liferay Portal Community Edition to version 6.0.6 GA or later.
Remote authenticated users of Liferay Portal Community Edition 6.x prior to 6.0.6 GA are affected by CVE-2011-1570.
CVE-2011-1570 is a Cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Liferay Portal Community Edition versions 6.0.0 to 6.0.5 are vulnerable to CVE-2011-1570.