Medium severity5.4NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026
CVE-2020-7934
CVE-2020-7934
Description
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | >= 7.1.0, < 7.3.0 | 7.3.0 |
Affected products
3- LifeRay/Portal CEdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-f99h-h678-fgg4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7934ghsaADVISORY
- semanticbits.com/liferay-portal-authenticated-xss-disclosure/nvdThird Party Advisory
- packetstormsecurity.com/files/160168/LifeRay-7.2.1-GA2-Cross-Site-Scripting.htmlnvdWEB
- web.archive.org/web/20200808034429/https://semanticbits.com/liferay-portal-authenticated-xss-disclosureghsaWEB
News mentions
0No linked articles in our index yet.