Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-78237

XSS vulnerability in Sites Settings portlet UI

    Details

      Description

      Steps to reproduce:

      1. Navigate to Control Panel > Sites > Sites
      2. Add site named <script>alert("XSS")</script>
      3. Save

      Or

      Open Configuration -> Site Settings of site '<script>alert("XSS")</script>' if it exists.

      Expected Result:
      No alert shows up.

      Actual Result:
      An alert shows up.

        Attachments

          Activity

            People

            Assignee:
            zoltan.csaszi Zoltán Császi (Inactive)
            Reporter:
            zoltan.csaszi Zoltán Császi (Inactive)
            Participants of an Issue:
            Recent user:
            Brian Wulbern
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Days since last comment:
              2 years, 39 weeks, 1 day ago

                Packages

                Version Package
                Master