CVE-2008-0181

Liferay Enterprise Portal - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.

Scores

EPSS 0.0144
EPSS Percentile 80.5%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

liferay/liferay_enterprise_portal

Timeline

Published Feb 05, 2008
Tracked Since Feb 18, 2026