CVE-2020-25476

Source
https://cve.org/CVERecord?id=CVE-2020-25476
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25476.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-25476
Aliases
Published
2021-01-07T17:15:12.590Z
Modified
2026-07-08T19:02:44.571966Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own profile, and the malicious payload will be injected and reflected in the calendar of the user who submitted the payload. An attacker could escalate its privileges in case an admin visits the calendar that injected the payload.

References

Affected packages

Git / github.com/liferay/liferay-portal

Affected ranges

Type
GIT
Repo
https://github.com/liferay/liferay-portal
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:liferay:liferay_portal:7.1.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:liferay:liferay_portal:7.2.1:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "7.1.3"
        },
        {
            "last_affected": "7.1.3"
        },
        {
            "introduced": "7.2.1"
        },
        {
            "last_affected": "7.2.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

7.*
7.1.3
7.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25476.json"