Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-863

Malicious JavaScript can be inserted into the Shopping portlet

Details

    Description

      Several cross site scripting (XSS) vulnerability exist in the Shopping portlet which may allow an attacker to insert malicious JavaScript into a page.

      Attachments

        Issue Links

          Activity

            People

              support-ee EE Support
              samuel.kong Samuel Kong
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP2 (5.1.5)