Description
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call
Remediation
References
https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3
http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
Related Vulnerabilities
CVE-2020-1728 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2018-8006 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2015-5170 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2023-24424 Vulnerability in maven package org.jenkins-ci.plugins:oic-auth
CVE-2023-41887 Vulnerability in maven package org.openrefine:database