Tribune

Home » Liferay Portal » English » 2. Using Liferay » General

Vista Combinata Vista Piatta Vista ad Albero
Discussioni [ Precedente | Successivo ]
toggle
Yves LeGrand
Blog-Portlet: Cross-Site Scripting Issue in Liferay 6 EE SP1
31 ottobre 2011 0.46
Risposta

Yves LeGrand

Punteggio: Regular Member

Messaggi: 158

Data di Iscrizione: 18 novembre 2009

Messaggi recenti

Hi Liferay.

I inserted a javascript-alert into the title of a blog. And it worked?
How is it possible to escape the html or javascript within a blogs title?

Is this a bug in Liferay 6 EE SP1?
How is it possible to fix this?

Best wishes,
Yves
Amos Fong
RE: Blog-Portlet: Cross-Site Scripting Issue in Liferay 6 EE SP1
24 ottobre 2011 19.34
Risposta

Amos Fong

LIFERAY STAFF

Punteggio: Liferay Legend

Messaggi: 1817

Data di Iscrizione: 7 ottobre 2008

Messaggi recenti

Hi Yves,

If you have an EE account I suggest you to open ticket with your account to get a faster response.

If not, I would try to reproduce it in latest trunk and open a ticket in LPS project with the appropriate security fields. If you can contribute a solution, that would be great, otherwise our security team can look at the issue and find a solution for it. If it's deemed an security issue, it should be backported and resolved in the next EE release.
Yves LeGrand
RE: Blog-Portlet: Cross-Site Scripting Issue in Liferay 6 EE SP1
25 ottobre 2011 0.34
Risposta

Yves LeGrand

Punteggio: Regular Member

Messaggi: 158

Data di Iscrizione: 18 novembre 2009

Messaggi recenti

Hi Amos.

It seems to be a bug which we have introduced by hooking into the Blog-Portlet.
So for the first I try to test this in a plain installation.

Sorry, maybe i have been too fast.

Merci,
Yves