Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-134338

The popup is shown when store XSS in page name during page creation

    Details

      Description

      Step to reproduce:

      1. Navigate to Pages admin
      2. Click the plus icon button > Public Page > Widget Page
      3. Type <script>alert(123);</script> in Name field
      4. Click Add

      Expected Results:
      There shouldn't be a popup.

      Actual Results:
      The 123 shown in a popup.

      Reproduced on:
      Tomcat 9.0.43 + MySQL 5.7. Portal master GIT ID: 5b29adeda9f3fed7bb05132807737da449bedb8b.

        Attachments

          Activity

            People

            Assignee:
            yang.cao Yang Cao
            Reporter:
            yang.cao Yang Cao
            Participants of an Issue:
            Recent user:
            Sophia Zhang
            Engineering Assignee:
            Lourdes Fernández Besada
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Days since last comment:
              24 weeks, 1 day ago

                Packages

                Version Package
                7.4.2 CE GA3 DXP 7,4
                7.4.13 DXP GA1
                Master