CVE-2011-1504

Liferay Portal 5.x and 6.x < 6.0.6 GA - Authenticated Cross-Site Scripting via Blog Title

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://issues.liferay.com/browse/LPS-11506
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/04/08/5
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/04/11/9
Various Sources x_refsource_misc
http://issues.liferay.com/browse/LPS-12145
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/29/1

Scores

EPSS 0.0034
EPSS Percentile 56.4%

Details

CWE
CWE-79
Status published
Products (15)
liferay/portal 5.0.0 rc
liferay/portal 5.0.1 rc
liferay/portal 5.1.0
liferay/portal 5.1.1
liferay/portal 5.1.2
liferay/portal 5.2.0
liferay/portal 5.2.1
liferay/portal 5.2.2
liferay/portal 5.2.3
liferay/portal 6.0.0
... and 5 more
Published May 07, 2011
Tracked Since Feb 18, 2026