CVE-2017-12646: XSS
Published Aug 7, 2017
·Updated
Cross-site scripting (XSS) exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
Other sources
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
Affected Software
4 affected componentsFixes available
Liferay Liferay Portal<=7.0
maven/com.liferay:com.liferay.login.web<1.1.20
1.1.20
maven/com.liferay:com.liferay.login.authentication.openid.connect.web=1.0.0
1.0.1
maven/com.liferay.portal:release.portal.bom<7.0.3-GA4
7.0.3-GA4
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·02:15 AM
Data Sourced
via GitHub·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-12646?
CVE-2017-12646 has a medium severity rating as it exposes users to potential cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-12646?
To fix CVE-2017-12646, upgrade Liferay Portal to version 7.0 CE GA4 or later.
3
Who is affected by CVE-2017-12646?
Users of Liferay Portal versions prior to 7.0 CE GA4 are affected by CVE-2017-12646.
4
What types of data are vulnerable in CVE-2017-12646?
CVE-2017-12646 allows for XSS through login names, passwords, or e-mail addresses.
5
How can I identify if my Liferay Portal is vulnerable to CVE-2017-12646?
Check the version of your Liferay Portal; if it is prior to 7.0 CE GA4, it is vulnerable to CVE-2017-12646.