Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1245

Malicious JavaScript can be inserted into the quick note portlet

Details

    Description

      A cross site scripting (XSS) vulnerability exists with display field in the quick note portlet. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page. To address this issue display field is escaped before text is displayed.

      Attachments

        Issue Links

          Activity

            People

              wesley.gong Wesley Gong
              wesley.gong Wesley Gong
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP4 (5.1.7)
                  5.2 EE SP2 (5.2.6)