Vulnerability Description
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Liferay Portal | <= 7.0 |
Related Weaknesses (CWE)
References
- https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferaIssue TrackingPatchVendor Advisory
- https://github.com/liferay/liferay-portal/commit/333f65bae9106182d12e02d249d4f95Issue TrackingPatchThird Party Advisory
- https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferaIssue TrackingPatchVendor Advisory
- https://github.com/liferay/liferay-portal/commit/333f65bae9106182d12e02d249d4f95Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2016-10404?
CVE-2016-10404 is a vulnerability with a CVSS score of 6.1 (MEDIUM). XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
How severe is CVE-2016-10404?
CVE-2016-10404 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10404?
Check the references section above for vendor advisories and patch information. Affected products include: Liferay Liferay Portal.