CVE-2011-1503

medium

Description

The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.

References

http://openwall.com/lists/oss-security/2011/04/11/9

http://openwall.com/lists/oss-security/2011/04/08/5

http://openwall.com/lists/oss-security/2011/03/29/1

http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952

http://issues.liferay.com/browse/LPS-13762

Details

Source: Mitre, NVD

Published: 2011-05-07

Updated: 2020-07-23

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium