CVE-2011-1504
Liferay Portal 5.x and 6.x < 6.0.6 GA - Authenticated Cross-Site Scripting via Blog Title
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.
References (6)
Core 6
Core References
Various Sources x_refsource_confirm
http://issues.liferay.com/browse/LPS-11506
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/04/08/5
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/04/11/9
Various Sources x_refsource_misc
http://issues.liferay.com/browse/LPS-12145
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/29/1
Various Sources x_refsource_confirm
http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952
Scores
EPSS
0.0034
EPSS Percentile
56.4%
Details
CWE
CWE-79
Status
published
Products (15)
liferay/portal
5.0.0 rc
liferay/portal
5.0.1 rc
liferay/portal
5.1.0
liferay/portal
5.1.1
liferay/portal
5.1.2
liferay/portal
5.2.0
liferay/portal
5.2.1
liferay/portal
5.2.2
liferay/portal
5.2.3
liferay/portal
6.0.0
... and 5 more
Published
May 07, 2011
Tracked Since
Feb 18, 2026