Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-58018

XSL Content portlet can be configured with any XML/XSL

Details

    Description

      The XSL Content portlet allows anyone who has permission to configure the portlet to specify any XML/XSL file. By creating the appropriate XML/XSL file, a user can access any file on the system, launch denial-of-service attacks and more.

      Attachments

        Activity

          People

            samuel.kong Samuel Kong
            samuel.kong Samuel Kong
            Rafaela Nascimento Rafaela Nascimento
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:
              7 years, 43 weeks, 3 days ago

              Packages

                Version Package
                6.0.X EE
                6.1.X EE
                6.2.X EE
                7.0.0 M5