CVE-2017-12649: XSS
Published Aug 7, 2017
·Updated
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
Affected Software
1 affected component
Liferay Liferay Portal<=7.0
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12649?
CVE-2017-12649 has been classified as a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How does CVE-2017-12649 impact Liferay Portal?
CVE-2017-12649 allows attackers to inject malicious scripts through crafted titles or summaries in the Web Content Display feature of Liferay Portal.
3
Which versions of Liferay Portal are affected by CVE-2017-12649?
CVE-2017-12649 affects Liferay Portal versions prior to 7.0 CE GA4.
4
How can I fix CVE-2017-12649?
To mitigate CVE-2017-12649, users should upgrade to Liferay Portal 7.0 CE GA4 or later.
5
What types of attacks can be executed using CVE-2017-12649?
Exploiting CVE-2017-12649 may allow attackers to perform Cross-Site Scripting (XSS) attacks, potentially compromising user sessions.