Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1485

Malicious JavaScript can be inserted into the Activities portlet

Details

    Description

      A cross site scripting (XSS) vulnerability exist with the Activities portlet which allows an attacker to insert malicious JavaScript into the page.

      Attachments

        Issue Links

          Activity

            People

              kristoffer.onias Kristoffer Onias
              samuel.kong Samuel Kong
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP2 (5.2.6)