Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2019-16891

Disclosure Date: October 04, 2019 (last updated November 27, 2024)
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Attacker Value
Unknown

CVE-2019-16147

Disclosure Date: September 09, 2019 (last updated November 27, 2024)
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.