← Back to CVE List

CVE-2019-6588

Published: 2019-06-03T20:29Z
Last Modified: 2024-11-21T04:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt