LSV-808: Reflected XSS in Kaleo Forms Admin

7.0 Fix Pack Version

99

7.1 Fix Pack Version

23

7.2 Fix Pack Version

12

7.3 Fix Pack Version

1

7.4 Fix Pack Version

None

CVE IDs

CVSS Base Score

CVSS Vector String

Description

Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the currentURL parameter.

Activity

Show:
Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Priority

Components

Zendesk Support

Created February 25, 2021 at 6:42 AM
Updated May 17, 2021 at 11:03 AM
Resolved March 17, 2021 at 4:10 AM