Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1661

Malicious JavaScript can be inserted into the Plugins Configuration section of Control Panel

Details

    Description

      A cross site scripting (XSS) vulnerability exist which allow an attacker to insert malicious JavaScript into the Plugins Configuration section of Control Panel (or the Plugins of Enterprise Admin portlet in 5.1.7).

      Attachments

        Issue Links

          Activity

            People

              kristoffer.onias Kristoffer Onias
              samuel.kong Samuel Kong
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP3 (5.2.7)