CVE-2020-7934
published 2020-01-28CVE-2020-7934: In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a…
PriorityP335medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EXPLOIT
EPSS
4.46%
90.4th percentile
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | 7.1.0 – 7.2.1 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
osv·2022-05-24
CVE-2020-7934 [MEDIUM] Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
In LifeRay Portal CE 7.1.0 through 7.2.1, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results).
GHSA
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
ghsa·2022-05-24
CVE-2020-7934 [MEDIUM] CWE-79 Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
In LifeRay Portal CE 7.1.0 through 7.2.1, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results).
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/160168/LifeRay-7.2.1-GA2-Cross-Site-Scripting.htmlhttps://github.com/3ndG4me/liferay-xss-7.2.1GA2-poc-report-CVE-2020-7934https://semanticbits.com/liferay-portal-authenticated-xss-disclosure/http://packetstormsecurity.com/files/160168/LifeRay-7.2.1-GA2-Cross-Site-Scripting.htmlhttps://github.com/3ndG4me/liferay-xss-7.2.1GA2-poc-report-CVE-2020-7934https://semanticbits.com/liferay-portal-authenticated-xss-disclosure/
2020-01-28
Published