vendor:
Liferay
by:
Fernando Câmara
6,1
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: Liferay
Affected Version From: < 6.2 CE GA6
Affected Version To: 7.0.0 CE RC1
Patch Exists: YES
Related CWE: CVE-2016-3670
CPE: a:liferay:liferay
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Stored Cross-Site Scripting Liferay CE
Liferay is vulnerable to a stored XSS when an user is created with an malicious payload on the FirstName field. The javascript payload is executed when another user tries to use the profile search section.
Mitigation:
Update to version 7.0.0 CE RC1