Liferay Portal Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-6588
In Liferay Portal before 7.1 CE GA4 an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the quoturlquot parameter of the JSP taglib call ltliferay-ui:captcha urlquotlt url gtquot /gt or ltliferay-captcha:captcha urlquotlt url gtquot /gt. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.