First published: Mon Jun 03 2019(Updated: )
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay Liferay Portal | <=6.0.6 | |
Liferay Liferay Portal | =6.1.0-b1 | |
Liferay Liferay Portal | =6.1.0-b2 | |
Liferay Liferay Portal | =6.1.0-b3 | |
Liferay Liferay Portal | =6.1.0-b4 | |
Liferay Liferay Portal | =6.1.0-ga1 | |
Liferay Liferay Portal | =6.1.0-rc1 | |
Liferay Liferay Portal | =6.1.1-ga2 | |
Liferay Liferay Portal | =6.1.2-ga3 | |
Liferay Liferay Portal | =6.2.0-b1 | |
Liferay Liferay Portal | =6.2.0-b2 | |
Liferay Liferay Portal | =6.2.0-ga1 | |
Liferay Liferay Portal | =6.2.0-m1 | |
Liferay Liferay Portal | =6.2.0-m2 | |
Liferay Liferay Portal | =6.2.0-m3 | |
Liferay Liferay Portal | =6.2.0-m4 | |
Liferay Liferay Portal | =6.2.0-m5 | |
Liferay Liferay Portal | =6.2.0-m6 | |
Liferay Liferay Portal | =6.2.0-rc1 | |
Liferay Liferay Portal | =6.2.0-rc2 | |
Liferay Liferay Portal | =6.2.0-rc3 | |
Liferay Liferay Portal | =6.2.0-rc4 | |
Liferay Liferay Portal | =6.2.0-rc5 | |
Liferay Liferay Portal | =6.2.0-rc6 | |
Liferay Liferay Portal | =6.2.1-ga2 | |
Liferay Liferay Portal | =6.2.2-ga3 | |
Liferay Liferay Portal | =6.2.3-ga4 | |
Liferay Liferay Portal | =6.2.4-ga5 | |
Liferay Liferay Portal | =6.2.5-ga6 | |
Liferay Liferay Portal | =7.0.0-a1 | |
Liferay Liferay Portal | =7.0.0-a2 | |
Liferay Liferay Portal | =7.0.0-a3 | |
Liferay Liferay Portal | =7.0.0-a4 | |
Liferay Liferay Portal | =7.0.0-a5 | |
Liferay Liferay Portal | =7.0.0-b1 | |
Liferay Liferay Portal | =7.0.0-b2 | |
Liferay Liferay Portal | =7.0.0-b3 | |
Liferay Liferay Portal | =7.0.0-b4 | |
Liferay Liferay Portal | =7.0.0-b5 | |
Liferay Liferay Portal | =7.0.0-b6 | |
Liferay Liferay Portal | =7.0.0-b7 | |
Liferay Liferay Portal | =7.0.0-ga1 | |
Liferay Liferay Portal | =7.0.0-m1 | |
Liferay Liferay Portal | =7.0.0-m2 | |
Liferay Liferay Portal | =7.0.0-m3 | |
Liferay Liferay Portal | =7.0.0-m4 | |
Liferay Liferay Portal | =7.0.0-m5 | |
Liferay Liferay Portal | =7.0.0-m6 | |
Liferay Liferay Portal | =7.0.0-m7 | |
Liferay Liferay Portal | =7.0.1-ga2 | |
Liferay Liferay Portal | =7.0.2-ga3 | |
Liferay Liferay Portal | =7.0.3-ga4 | |
Liferay Liferay Portal | =7.0.4-ga5 | |
Liferay Liferay Portal | =7.0.5-ga6 | |
Liferay Liferay Portal | =7.0.6-ga7 | |
Liferay Liferay Portal | =7.1.0-a1 | |
Liferay Liferay Portal | =7.1.0-a2 | |
Liferay Liferay Portal | =7.1.0-b1 | |
Liferay Liferay Portal | =7.1.0-b2 | |
Liferay Liferay Portal | =7.1.0-b3 | |
Liferay Liferay Portal | =7.1.0-ga1 | |
Liferay Liferay Portal | =7.1.0-m1 | |
Liferay Liferay Portal | =7.1.0-m2 | |
Liferay Liferay Portal | =7.1.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.