<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>AntiSamy Liferay 7.0</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=118233519" />
  <subtitle>AntiSamy Liferay 7.0</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=118233519</id>
  <updated>2026-04-04T21:28:50Z</updated>
  <dc:date>2026-04-04T21:28:50Z</dc:date>
  <entry>
    <title>RE: AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118428111" />
    <author>
      <name>Iñigo Boyano</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118428111</id>
    <updated>2020-02-05T08:01:31Z</updated>
    <published>2020-02-05T08:01:31Z</published>
    <summary type="html">Hi, &lt;br /&gt;Finally, the theme was right but the problems was in our ADT to print the breadcrumb. I saw that in the breadcrumb&amp;#39;s ADT of liferay, the title was escaped manually and in ours ADT i didn´t do it. &lt;br /&gt;&lt;br /&gt;Using the htmlUtil.escape() method when I print the breadcrumbs title  , the problem was solved.Now, I have the same vulnerability in our web content custom templates. I thougth that the antisamy property should do this task, but I tried several configurations and none works like i wish.&lt;br /&gt;&lt;br /&gt;Have I to escape manually all the custom fileds in all of my custom templates with the method htmlUtil or there is any configuration to escape the values of the fields of my custom templates?&lt;br /&gt;&lt;br /&gt;Kind regards,&lt;br /&gt;&lt;br /&gt;Iñigo</summary>
    <dc:creator>Iñigo Boyano</dc:creator>
    <dc:date>2020-02-05T08:01:31Z</dc:date>
  </entry>
  <entry>
    <title>RE: AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118284259" />
    <author>
      <name>Iñigo Boyano</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118284259</id>
    <updated>2020-01-16T09:00:09Z</updated>
    <published>2020-01-16T09:00:09Z</published>
    <summary type="html">Hi,&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve found that this problem occurs only wiht my custom theme.&lt;br /&gt;&lt;br /&gt;If I set the classic theme of liferay or other custom theme develop by me, the antisamy works properly.&lt;br /&gt;&lt;br /&gt;Anyone has any idea of what can have my theme for what the antisamy is not working??&lt;br /&gt;&lt;br /&gt;Kind regards,&lt;br /&gt;&lt;br /&gt;Iñigo</summary>
    <dc:creator>Iñigo Boyano</dc:creator>
    <dc:date>2020-01-16T09:00:09Z</dc:date>
  </entry>
  <entry>
    <title>RE: AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118245090" />
    <author>
      <name>Tomáš Polešovský</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118245090</id>
    <updated>2020-01-10T09:14:10Z</updated>
    <published>2020-01-10T09:14:10Z</published>
    <summary type="html">Ah, ok. Have you tried to contact the support? They should help you better, they know your environment and have the bandwith to help you. Thanks!</summary>
    <dc:creator>Tomáš Polešovský</dc:creator>
    <dc:date>2020-01-10T09:14:10Z</dc:date>
  </entry>
  <entry>
    <title>RE: AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118234950" />
    <author>
      <name>Iñigo Boyano</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118234950</id>
    <updated>2020-01-09T11:17:13Z</updated>
    <published>2020-01-09T11:17:13Z</published>
    <summary type="html">Sorry Tomas,&lt;br /&gt;I wasn&amp;#39;t precise about the version i&amp;#39;m using, is not community, is DXP.&lt;br /&gt;Particulary, is the next version:&lt;br /&gt;&lt;ul style="list-style: disc outside;"&gt;&lt;li&gt;Liferay 7 DXP, build number: 7010&lt;/li&gt;&lt;li&gt;FixPaxk: 88-7010.&lt;/li&gt;&lt;/ul&gt;</summary>
    <dc:creator>Iñigo Boyano</dc:creator>
    <dc:date>2020-01-09T11:17:13Z</dc:date>
  </entry>
  <entry>
    <title>RE: AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118234593" />
    <author>
      <name>Tomáš Polešovský</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118234593</id>
    <updated>2020-01-09T10:50:05Z</updated>
    <published>2020-01-09T10:50:05Z</published>
    <summary type="html">Hi,&lt;br /&gt;I couldn&amp;#39;t reproduce it on 7.0 GA3. Maybe it&amp;#39;s fixed? &lt;br /&gt;Btw. 7.0 is very outdated community version, I strongly recommend to upgrade, there were more serious issues than just XSS, look at &lt;a href="https://portal.liferay.dev/learn/security/known-vulnerabilities"&gt;https://portal.liferay.dev/learn/security/known-vulnerabilities&lt;/a&gt;. &lt;br /&gt;Sincerely,&lt;br /&gt;-- tom +</summary>
    <dc:creator>Tomáš Polešovský</dc:creator>
    <dc:date>2020-01-09T10:50:05Z</dc:date>
  </entry>
  <entry>
    <title>AntiSamy Liferay 7.0</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118233518" />
    <author>
      <name>Iñigo Boyano</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118233518</id>
    <updated>2020-01-09T09:24:19Z</updated>
    <published>2020-01-09T09:24:19Z</published>
    <summary type="html">Hi, I have a security vulnerability about cross site scripting (XSS stored) in the liferay forum portlet (com_liferay_message_boards_web_portlet_MBPortlet).&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve been searching a solution in the web and i&amp;#39;ve fount the following link in liferay documentation about antiSamy.&lt;br /&gt;&lt;a href="https://portal.liferay.dev/docs/7-0/deploy/-/knowledge_base/d/antisamy"&gt;https://portal.liferay.dev/docs/7-0/deploy/-/knowledge_base/d/antisamy&lt;/a&gt;&lt;br /&gt;&lt;a href="https://portal.liferay.dev/docs/7-0/deploy/-/knowledge_base/d/antisamy"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="https://portal.liferay.dev/docs/7-0/deploy/-/knowledge_base/d/antisamy"&gt;&lt;/a&gt;I&amp;#39;ve configured the antiSamy like link said in order to cannot put script tags in the forums fields:&lt;br /&gt;&lt;ul style="list-style: disc outside;"&gt;&lt;li&gt;Whitelist = *&lt;/li&gt;&lt;li&gt;Blacklist = com.liferay.message.boards.*&lt;/li&gt;&lt;/ul&gt;Besides, i&amp;#39;ve checked the sanitizer-configuration.xml file and the script tag is inside with the &amp;#34;remove&amp;#34; action.&lt;br /&gt;&lt;br /&gt;Can I avoid the user use script tags in the creation of new forum thread or new forum category?&lt;br /&gt;&lt;br /&gt;The test i&amp;#39;ve made is tu put &amp;lt;script&amp;gt;alert(&amp;#34;xss&amp;#34;)&amp;lt;/script&amp;gt; in category name and when i open this category, the alert show up.&lt;br /&gt;&lt;br /&gt;Kind regards,&lt;br /&gt;&lt;br /&gt; Íñigo</summary>
    <dc:creator>Iñigo Boyano</dc:creator>
    <dc:date>2020-01-09T09:24:19Z</dc:date>
  </entry>
</feed>
