← Back

CVE-2019-6588

nvd nist
Published: Jun 3, 2019Modified: Nov 21, 2024

JSON object

Loading...
4.7
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.7
Source: NVD

Description

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.

Affected (64)

1 product
Liferay Portal
Configuration A
64 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Up to 6.0.6
Version 6.1.0 b1
Version 6.1.0 b2
Version 6.1.0 b3
Version 6.1.0 b4
Version 6.1.0 ga1
Version 6.1.0 rc1
Version 6.1.1 ga2
Version 6.1.2 ga3
Version 6.2.0 b1
Version 6.2.0 b2
Version 6.2.0 ga1
Version 6.2.0 m1
Version 6.2.0 m2
Version 6.2.0 m3
Version 6.2.0 m4
Version 6.2.0 m5
Version 6.2.0 m6
Version 6.2.0 rc1
Version 6.2.0 rc2
Version 6.2.0 rc3
Version 6.2.0 rc4
Version 6.2.0 rc5
Version 6.2.0 rc6
Version 6.2.1 ga2
Version 6.2.2 ga3
Version 6.2.3 ga4
Version 6.2.4 ga5
Version 6.2.5 ga6
Version 7.0.0 a1
Version 7.0.0 a2
Version 7.0.0 a3
Version 7.0.0 a4
Version 7.0.0 a5
Version 7.0.0 b1
Version 7.0.0 b2
Version 7.0.0 b3
Version 7.0.0 b4
Version 7.0.0 b5
Version 7.0.0 b6
Version 7.0.0 b7
Version 7.0.0 ga1
Version 7.0.0 m1
Version 7.0.0 m2
Version 7.0.0 m3
Version 7.0.0 m4
Version 7.0.0 m5
Version 7.0.0 m6
Version 7.0.0 m7
Version 7.0.1 ga2
Version 7.0.2 ga3
Version 7.0.3 ga4
Version 7.0.4 ga5
Version 7.0.5 ga6
Version 7.0.6 ga7
Version 7.1.0 a1
Version 7.1.0 a2
Version 7.1.0 b1
Version 7.1.0 b2
Version 7.1.0 b3
Version 7.1.0 ga1
Version 7.1.0 m1
Version 7.1.0 m2
Version 7.1.0 rc1

Timeline

No history available yet.