ZeroHour

CVE-2016-10404

CVSS 3.0
6.1 medium
EPSS
<1%p53
Published
()
Modified
Description

XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.

Vendors
liferay
Products
liferay portal
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.