GHSA-hwp2-gvm5-452f
Dashboard / Vulnerabilities / GHSA-hwp2-gvm5-452f
Summary: Liferay Portal Allows Cross-Site Scripting (XSS) via the SimpleCaptcha API
Details: In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-6588, https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3, https://github.com/liferay/liferay-portal, http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
Affected packages
Package
Name: com.liferay.portal:release.portal.bom
Purl: pkg:maven/com.liferay.portal/release.portal.bom
Affected ranges
Type: ECOSYSTEM
Events:
