Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-22613

XSS vulnerability in calendar portlet (location)

    Details

      Description

      There is a XSS vulnerability in calendar portlet by entering something like
      <script>alert('Cross Site Scripting');</script>
      into "location" field (by creating an event)

        Attachments

          Activity

            People

            Assignee:
            sophia.zhang Sophia Zhang
            Reporter:
            mabu Maximilian Butterer (Inactive)
            Participants of an Issue:
            Recent user:
            Esther Sanz
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Days since last comment:
              10 years, 3 weeks, 3 days ago

                Packages

                Version Package
                --Sprint 12/11
                6.1.0 CE RC1