CVE-2019-6588 – Liferay Portal < 7.1 CE GA4 / SimpleCaptcha API XSS

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url…

Google XSS Game

I recently found this webpage (created by Google) which provides a cross-site-scripting game to test your skills in Javascript. It is divided into 6 levels. I found the first,second,third and fifth level pretty easy, but I think the fourth and sixth…

