CVE-2019-6588
- EPSS 0.69%
- Published 03.06.2019 20:29:01
- Last modified 21.11.2024 04:46:45
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha ur...
- EPSS 44.69%
- Published 22.04.2019 11:29:05
- Last modified 21.11.2024 04:21:05
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_scri...
CVE-2018-10795
- EPSS 0.36%
- Published 07.05.2018 13:29:00
- Last modified 21.11.2024 03:42:02
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/ed...
CVE-2017-1000425
- EPSS 0.26%
- Published 02.01.2018 23:29:00
- Last modified 21.11.2024 03:04:42
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
CVE-2017-17868
- EPSS 0.24%
- Published 27.12.2017 17:08:20
- Last modified 20.04.2025 01:37:25
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
CVE-2016-10404
- EPSS 0.25%
- Published 07.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
CVE-2017-12645
- EPSS 0.24%
- Published 07.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
CVE-2017-12646
- EPSS 0.25%
- Published 07.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
CVE-2017-12647
- EPSS 0.25%
- Published 07.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
CVE-2017-12648
- EPSS 0.25%
- Published 07.08.2017 16:29:00
- Last modified 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.