Liferay

Liferay Portal

180 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Published 03.06.2019 20:29:01
  • Last modified 21.11.2024 04:46:45

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha ur...

Exploit
  • EPSS 44.69%
  • Published 22.04.2019 11:29:05
  • Last modified 21.11.2024 04:21:05

An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_scri...

Exploit
  • EPSS 0.36%
  • Published 07.05.2018 13:29:00
  • Last modified 21.11.2024 03:42:02

Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/ed...

  • EPSS 0.26%
  • Published 02.01.2018 23:29:00
  • Last modified 21.11.2024 03:04:42

Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.

Exploit
  • EPSS 0.24%
  • Published 27.12.2017 17:08:20
  • Last modified 20.04.2025 01:37:25

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

  • EPSS 0.25%
  • Published 07.08.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.

  • EPSS 0.24%
  • Published 07.08.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.

  • EPSS 0.25%
  • Published 07.08.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.

  • EPSS 0.25%
  • Published 07.08.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.

  • EPSS 0.25%
  • Published 07.08.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.