Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-2030

Severity
4.3MEDIUM
EPSS
1.5%
top 18.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 22
Latest updateApr 29

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xh4h-8w7q-32rw: Multiple cross-site scripting (XSS) vulnerabilities in index2022-04-29
CVEList
CVE-2004-2030: Multiple cross-site scripting (XSS) vulnerabilities in index2005-05-10

💥Exploits & PoCs

1
Exploit-DB
Liferay Enterprise Portal 1.x/2.x/5.0.2 - Multiple Cross-Site Scripting Vulnerabilities2004-05-22
CVE-2004-2030 (MEDIUM CVSS 4.3) | Multiple cross-site scripting (XSS) | cvebase.io