Multiple Cross-Site Scripting Vulnerabilities in Novell Teaming Portal
CVE-2009-1294

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
16 April 2009

Summary

The Novell Teaming portal version 1.0 through SP3 (1.0.3) and Liferay 4.3.0 are susceptible to multiple cross-site scripting (XSS) vulnerabilities. Attackers can manipulate web scripts or HTML content through the p_p_state and p_p_mode parameters, potentially leading to unauthorized access or data breaches. These vulnerabilities enable remote attackers to execute malicious scripts in the context of the user's session, compromising the integrity and security of the web application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.