Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content Display
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Aug 8, 2025
Package
Affected versions
< 7.0.3-ga4
Patched versions
7.0.3-ga4
Description
Published by the National Vulnerability Database
Aug 7, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Aug 8, 2025
Last updated
Aug 8, 2025
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
References