CVE-2021-33326Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 38.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 24

Description

Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module2022-05-24
GHSA
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module2022-05-24
CVEList
CVE-2021-33326: Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 72021-08-03
CVE-2021-33326 — Cross-site Scripting in Liferay Portal | cvebase