CVE-2017-12647: XSS
Published Aug 7, 2017
·Updated
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
Affected Software
1 affected component
Liferay Liferay Portal<=7.0
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12647?
CVE-2017-12647 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2017-12647?
To fix CVE-2017-12647, upgrade to Liferay Portal version 7.0 CE GA5 or later.
3
What products are affected by CVE-2017-12647?
CVE-2017-12647 affects Liferay Portal versions up to and including 7.0 CE GA4.
4
What type of vulnerability is CVE-2017-12647?
CVE-2017-12647 is a Cross-Site Scripting (XSS) vulnerability in the Knowledge Base article title feature.
5
Can CVE-2017-12647 result in data exposure?
Yes, CVE-2017-12647 can potentially lead to user data exposure through XSS attacks.