GHSA-f99h-h678-fgg4

Suggest an improvement
Source
https://github.com/advisories/GHSA-f99h-h678-fgg4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f99h-h678-fgg4/GHSA-f99h-h678-fgg4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f99h-h678-fgg4
Aliases
Published
2022-05-24T17:07:37Z
Modified
2025-04-28T19:42:18Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
Details

In LifeRay Portal CE 7.1.0 through 7.2.1, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results).

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-28T19:21:10Z",
    "nvd_published_at":  "2020-01-28T14:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.3.0

Affected versions

7.*
7.1.0
7.1.1
7.1.2
7.1.3
7.1.3-1
7.2.0
7.2.1
7.2.1-1

Database specific

last_known_affected_version_range
"<= 7.2.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f99h-h678-fgg4/GHSA-f99h-h678-fgg4.json"