PT-2008-1827 · Liferay · Liferay Portal

Tomasz Kuczynski

·

Published

2008-02-04

·

Updated

2008-09-05

·

CVE-2008-0181

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal version 4.3.6
Description A cross-site scripting (XSS) issue exists in the Admin portlet, allowing remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.
Recommendations For Liferay Portal version 4.3.6, consider disabling the Admin portlet or restricting access to it until a fix is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0181

Affected Products

Liferay Portal