Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-13762

XSL Content Portlet can utilize file:/// to potentially access files on the system

Details

    • 6.0.x, 5.2.x, 5.1.x
    • Committed

    Description

      The XSL Content Portlet paths for XSL and XML content accept the "file:///" path, granting it access to files across the system and outside of the path for the appserver. As is, the portlet only reads XSL and XML content, but can pose a further risk.

      Attachments

        Issue Links

          Activity

            People

              hugo.huijser Hugo Huijser (Inactive)
              jonas.choi Jonas Choi (Inactive)
              Kiyoshi Lee Kiyoshi Lee
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                12 years, 31 weeks, 3 days ago

                Packages

                  Version Package
                  6.0.6 GA
                  6.1.0 CE RC1