Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-22613

XSS vulnerability in calendar portlet (location)

Details

    Description

      There is a XSS vulnerability in calendar portlet by entering something like
      <script>alert('Cross Site Scripting');</script>
      into "location" field (by creating an event)

      Attachments

        Activity

          People

            sophia.zhang Sophia Zhang
            mabu Maximilian Butterer (Inactive)
            Kiyoshi Lee Kiyoshi Lee
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:
              11 years, 4 weeks, 5 days ago

              Packages

                Version Package
                --Sprint 12/11
                6.1.0 CE RC1