Cross-Site Scripting Vulnerability in Liferay Portal by Liferay
CVE-2008-0178

Currently unrated

Key Information:

Vendor

Liferay

Vendor
CVE Published:
5 February 2008

What is CVE-2008-0178?

Liferay Portal 4.3.6 contains a cross-site scripting vulnerability within the Enterprise Admin Session Monitoring component. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML into web pages by manipulating the User-Agent HTTP header. Successful exploitation could lead to malicious activities, including data theft and unauthorized actions performed on behalf of other users.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.