Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1617

Malicious JavaScript can be inserted into the Language portlet

Details

    Description

      A cross site scripting (XSS) vulnerability exist with the Language portlet which allows an attacker to insert malicious JavaScript into the page.

      Attachments

        Issue Links

          Activity

            People

              kristoffer.onias Kristoffer Onias
              brian.chan Brian Chan
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP3 (5.2.7)