CVE-2020-7934
- EPSS 3.29%
- Veröffentlicht 28.01.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:38:02
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it...
CVE-2019-16891
- EPSS 85.47%
- Veröffentlicht 04.10.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:17
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CVE-2019-16147
- EPSS 0.24%
- Veröffentlicht 09.09.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:08
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
CVE-2019-6588
- EPSS 0.69%
- Veröffentlicht 03.06.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:45
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha ur...
- EPSS 44.69%
- Veröffentlicht 22.04.2019 11:29:05
- Zuletzt bearbeitet 21.11.2024 04:21:05
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_scri...
CVE-2018-10795
- EPSS 0.34%
- Veröffentlicht 07.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:02
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/ed...
CVE-2017-1000425
- EPSS 0.26%
- Veröffentlicht 02.01.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:42
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
CVE-2017-17868
- EPSS 0.24%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
CVE-2016-10404
- EPSS 0.25%
- Veröffentlicht 07.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
CVE-2017-12645
- EPSS 0.24%
- Veröffentlicht 07.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.