In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
2019-06-03T20:29:01.547
2024-11-21T04:46:45.383
Modified
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | liferay | liferay_portal | ≤ 6.0.6 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.0 | Yes |
Application | liferay | liferay_portal | 6.1.1 | Yes |
Application | liferay | liferay_portal | 6.1.2 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.0 | Yes |
Application | liferay | liferay_portal | 6.2.1 | Yes |
Application | liferay | liferay_portal | 6.2.2 | Yes |
Application | liferay | liferay_portal | 6.2.3 | Yes |
Application | liferay | liferay_portal | 6.2.4 | Yes |
Application | liferay | liferay_portal | 6.2.5 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.0 | Yes |
Application | liferay | liferay_portal | 7.0.1 | Yes |
Application | liferay | liferay_portal | 7.0.2 | Yes |
Application | liferay | liferay_portal | 7.0.3 | Yes |
Application | liferay | liferay_portal | 7.0.4 | Yes |
Application | liferay | liferay_portal | 7.0.5 | Yes |
Application | liferay | liferay_portal | 7.0.6 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |
Application | liferay | liferay_portal | 7.1.0 | Yes |