Overview
Liferay Portal fails to properly validate the User Profile "Greeting" value, which can allow script to execute when a user logs into the portal.
Description
Liferay Portal is an enterprise portal solution that uses Java technologies. The User Profile "Greeting" value of Liferay Portal fails to properly sanitize input. |
Impact
An authenticated user may be able to inject script into the "Greeting" for the portal. |
Solution
Apply an update This issue is addressed in Liferay versions 4.4.0 and 4.3.7, as specified in Liferay support document LEP-4738. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Tomasz Kuczynski for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2008-0180 |
Severity Metric: | 0.11 |
Date Public: | 2008-01-10 |
Date First Published: | 2008-01-31 |
Date Last Updated: | 2008-01-31 19:51 UTC |
Document Revision: | 1 |