CVE-2019-16147Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 52.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 9
Latest updateMay 24

Description

Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDliferay/liferay_portal< 7.2.0+1

Patches

🔴Vulnerability Details

3
OSV
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via a Journal Article Title2022-05-24
GHSA
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via a Journal Article Title2022-05-24
CVEList
CVE-2019-16147: Liferay Portal through 72019-09-09
CVE-2019-16147 — Cross-site Scripting in Liferay Portal | cvebase