XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-08-07T16:00:00Z

Updated: 2024-09-16T20:12:18.146Z

Reserved: 2017-08-07T00:00:00Z

Link: CVE-2016-10404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-08-07T16:29:00.190

Modified: 2024-11-21T02:43:56.133

Link: CVE-2016-10404

cve-icon Redhat

No data.