Executive Summary

This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Title Liferay Portal PCE contains multiple cross-site scripting vulnerabilities
Name VU#100972 First vendor Publication 2014-07-09
Vendor VU-CERT Last vendor Modification 2014-07-10
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


Vulnerability Note VU#100972

Liferay Portal PCE contains multiple cross-site scripting vulnerabilities

Original Release date: 09 Jul 2014 | Last revised: 10 Jul 2014


Liferay Portal versions 6.1.2 CE GA3, 6.1.X EE, 6.2.X EE, Master contain multiple cross-site scripting vulnerabilities


CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2014-2963

Liferay is affected by a Persistent Cross Site Scripting vulnerability in the "my account area".
The specific versions affected are: Liferay Portal Community Edition 6.1.2 CE GA3, 6.1.X EE, 6.2.X EE, Master
Three instances of this issue were identified, at the following locations/parameters:

/group/control_panel/manage [_2_firstName parameter]
/group/control_panel/manage [_2_lastName parameter]
/group/control_panel/manage [_2_middleName parameter]


An attacker with access to the Liferay Portal "my account area" or by tricking a logged in user to visit a specially crafted URL, can conduct a cross-site scripting attack, which could be used to result in information leakage, privilege escalation, and/or denial of service.


Apply an Update
This vulnerability was addressed on 06/04/14, bug id LPS-46156.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
Liferay, Inc.Affected07 May 201409 Jul 2014
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)



  • https://github.com/samuelkong/liferay-portal
  • http://www.liferay.com/


Thanks to Simone Cecchini from Verizon Enterprise Solutions GCIS Threat and Vulnerability Management for reporting this vulnerability.

This document was written by Chris King.

Other Information

  • CVE IDs:CVE-2014-2963
  • Date Public:09 Jul 2014
  • Date First Published:09 Jul 2014
  • Date Last Updated:10 Jul 2014
  • Document Revision:10


If you have feedback, comments, or additional information about this vulnerability, please send us email.

Original Source

Url : http://www.kb.cert.org/vuls/id/100972

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

Application 3

Alert History

If you want to see full details history, please login or register.
Date Informations
2014-07-25 13:18:48
  • Multiple Updates
2014-07-10 21:27:22
  • Multiple Updates
2014-07-10 17:28:53
  • Multiple Updates
2014-07-10 17:24:23
  • Multiple Updates
2014-07-09 21:22:34
  • First insertion