CVE-2017-1000425
02.01.2018, 23:29
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
Vendor | Product | Version |
---|---|---|
liferay | liferay_portal | 𝑥 < 7.0.3_ga4 |
𝑥
= Vulnerable software versions
References