{"id":"GHSA-m2gx-7pvx-3gvg","summary":"Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via a Journal Article Title","details":"Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to `journal_article/page.jsp` in `journal/journal-taglib`.","aliases":["CVE-2019-16147"],"modified":"2025-04-28T19:42:18.585865Z","published":"2022-05-24T16:55:43Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-28T19:11:06Z","nvd_published_at":"2019-09-09T21:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16147"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/7e063aed70f947a92bb43a4471e0c4e650fe8f7f"},{"type":"PACKAGE","url":"https://github.com/liferay/liferay-portal"}],"affected":[{"package":{"name":"com.liferay:com.liferay.journal.taglib","ecosystem":"Maven","purl":"pkg:maven/com.liferay/com.liferay.journal.taglib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.4"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.20","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","3.0.0","3.0.1","3.0.2","3.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m2gx-7pvx-3gvg/GHSA-m2gx-7pvx-3gvg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}