CVE-2021-29039Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 35.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Latest updateMay 24

Description

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page2022-05-24
OSV
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page2022-05-24
CVEList
CVE-2021-29039: Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 72021-05-16
CVE-2021-29039 — Cross-site Scripting in Liferay Portal | cvebase