XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.liferay.portal:release.portal.bom(Maven) | 0 | 7.0.3-GA4 | N/A |
| com.liferay:com.liferay.login.authentication.openid.connect.web(Maven) | 1.0.0 | 1.0.1 | N/A |
| com.liferay:com.liferay.login.web(Maven) | 0 | 1.1.20 | N/A |
CVSS Metrics