CVE-2019-6588 EXPLOIT
4.7
MEDIUM · CVSS 3.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
Scoring
| CVSS | 4.7 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.3% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-06-03 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| liferay | liferay portal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting | 2019-06-11 |
References
- http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
- https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3
- http://packetstormsecurity.com/files/153252/Liferay-Portal-7.1-CE-GA4-Cross-Site-Scripting.html
- https://dev.liferay.com/web/community-security-team/known-vulnerabilities/liferay-portal-71/-/asset_publisher/7v4O7y85hZMo/content/cst-7130-multiple-xss-vulnerabilities-in-7-1-ce-ga3
→ the Explorer · watch your stack · NVD