Cross-Site Scripting Vulnerability in Liferay Portal by Liferay
CVE-2008-0180

Currently unrated

Key Information:

Vendor

Liferay

Vendor
CVE Published:
5 February 2008

What is CVE-2008-0180?

A cross-site scripting (XSS) vulnerability exists in the Liferay Portal, specifically in the themes/_unstyled/templates/init.vm file. This flaw allows remote authenticated users to inject malicious web scripts or HTML into the Greeting field of a User Profile, potentially compromising the integrity of the web application and exposing users to various security risks.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.