Medium severity6.1NVD Advisory· Published Jan 7, 2021· Updated Jun 17, 2026
CVE-2020-25476
CVE-2020-25476
Description
Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own profile, and the malicious payload will be injected and reflected in the calendar of the user who submitted the payload. An attacker could escalate its privileges in case an admin visits the calendar that injected the payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | <= 7.1.3 | — |
com.liferay.portal:release.portal.bomMaven | >= 7.2, <= 7.2.1 | — |
Affected products
4- Liferay/CMS Portaldescription
Patches
Vulnerability mechanics
References
5- github.com/community-security-team/liferay-portal/compare/7.1.3-ga4...7.1.3-cumulative.patchnvdPatchThird Party AdvisoryWEB
- github.com/community-security-team/liferay-portal/compare/7.2.1-ga2...7.2.1-cumulative.patchnvdPatchThird Party AdvisoryWEB
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119318646nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-pvpg-9553-f979ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-25476ghsaADVISORY
News mentions
0No linked articles in our index yet.