6.1
CVSSv3

CVE-2016-3670

Published: 13/06/2016 Updated: 20/06/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay prior to 7.0.0 CE RC1 allows remote malicious users to inject arbitrary web script or HTML via the FirstName field.

Vulnerable Product Search on Vulmon Subscribe to Product

liferay liferay portal

Exploits

CVE-2016-3670 Stored Cross Site Scripting in Liferay CE 1 Vulnerability Properties Title: Stored Cross-Site Scripting Liferay CE CVE ID: CVE-2016-3670 CVSSv3 Base Score: 46 (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N) Vendor: Liferay Inc Products: Liferay Advisory Release Date: 27 May 2016 Advisory URL: labsintegritypt/advisories/cve-2016-36 ...
Liferay CE versions prior to 62 CE GA6 suffer from a persistent cross site scripting vulnerability ...