CVE-2017-17868 — Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 52.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 27
Latest updateMay 14

Description

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

â–¶NVDliferay/liferay_portal6.1.0

🔴Vulnerability Details

2
GHSA
GHSA-37m5-593h-89wf: In Liferay Portal 6↗2022-05-14
â–¶
CVEList
CVE-2017-17868: In Liferay Portal 6↗2017-12-23
â–¶
CVE-2017-17868 — Cross-site Scripting in Liferay Portal | cvebase