CVE-2017-12648: XSS
Published Aug 7, 2017
·Updated
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
Affected Software
3 affected componentsFixes available
Liferay Liferay Portal<=7.0
maven/com.liferay:com.liferay.frontend.taglib<2.1.3
2.1.3
maven/com.liferay.portal:release.portal.bom<7.0.3-GA4
7.0.3-GA4
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·02:15 AM
Data Sourced
via GitHub·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-12648?
CVE-2017-12648 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-12648?
To fix CVE-2017-12648, update Liferay Portal to version 7.0 CE GA4 or later.
3
What type of vulnerability is CVE-2017-12648?
CVE-2017-12648 is a cross-site scripting (XSS) vulnerability.
4
In which versions of Liferay Portal is CVE-2017-12648 present?
CVE-2017-12648 affects Liferay Portal versions before 7.0 CE GA4.
5
What can attackers do with CVE-2017-12648?
Attackers can exploit CVE-2017-12648 to execute arbitrary scripts in the context of a victim's browser.