Arbitrary Web Script Injection via Blog Title in Liferay Portal Community Edition (CE) 5.x and 6.x

Arbitrary Web Script Injection via Blog Title in Liferay Portal Community Edition (CE) 5.x and 6.x

CVE-2011-1504 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.

Learn more about our Web App Pen Testing.