Multiple Cross-Site Scripting Vulnerabilities in Novell Teaming Portal
CVE-2009-1294
Currently unrated
Key Information:
- Vendor
- Novell
- Vendor
- CVE Published:
- 16 April 2009
Summary
The Novell Teaming portal version 1.0 through SP3 (1.0.3) and Liferay 4.3.0 are susceptible to multiple cross-site scripting (XSS) vulnerabilities. Attackers can manipulate web scripts or HTML content through the p_p_state and p_p_mode parameters, potentially leading to unauthorized access or data breaches. These vulnerabilities enable remote attackers to execute malicious scripts in the context of the user's session, compromising the integrity and security of the web application.
References
Timeline
Vulnerability published
Vulnerability Reserved