4.7

CVE-2019-6588

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal SwEdition community Version <= 6.0.6
Liferay ≫ Liferay Portal Version 6.1.0 Update b1 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.0 Update b2 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.0 Update b3 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.0 Update b4 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.0 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.0 Update rc1 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.1 Update ga2 SwEdition community
Liferay ≫ Liferay Portal Version 6.1.2 Update ga3 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update b1 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update b2 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m1 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m2 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m3 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m4 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m5 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update m6 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc1 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc2 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc3 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc4 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc5 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.0 Update rc6 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.1 Update ga2 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.2 Update ga3 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.3 Update ga4 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.4 Update ga5 SwEdition community
Liferay ≫ Liferay Portal Version 6.2.5 Update ga6 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update a1 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update a2 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update a3 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update a4 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update a5 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b1 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b2 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b3 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b4 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b5 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b6 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update b7 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m1 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m2 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m3 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m4 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m5 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m6 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.0 Update m7 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.1 Update ga2 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.2 Update ga3 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.3 Update ga4 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.4 Update ga5 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.5 Update ga6 SwEdition community
Liferay ≫ Liferay Portal Version 7.0.6 Update ga7 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update a1 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update a2 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update b1 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update b2 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update b3 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update m1 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update m2 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.0 Update rc1 SwEdition community
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.28% 0.809
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1.6 2.7
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3
Vendor Advisory