CVE-2020-7934 is a persistent cross-site scripting (XSS) vulnerability affecting Liferay Portal CE versions 7.1.0 through 7.2.1 GA2. An authenticated user can inject malicious scripts into their user profile fields (First Name, Middle Name, Last Name), which are then stored in the database. When other users perform a search that includes the compromised user, the XSS payload is rendered, potentially leading to information disclosure or session hijacking. Rated as Medium severity (CVSS 5.4), this vulnerability requires user interaction (UI:R) and low privileges (PR:L) for exploitation. The attack complexity is low (AC:L), and it can impact confidentiality (C:L) and integrity (I:L). While not listed on the CISA KEV catalog, an exploit (EDB-49091) is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, and the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0, <= 7.2.1CPE matchmatch criteria | cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.