CVE-2019-6588
—CVSS 3.0
4.7 medium
EPSS
2%p82
Published
()
Modified
Description
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call " /> or " />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
- Vendors
- liferay
- Products
- liferay portal
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.