CVE-2021-38264Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateMar 4

Description

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDliferay/liferay_portal7.4.0, 7.4.1+1

Patches

🔴Vulnerability Details

3
GHSA
Liferay Portal vulnerable to cross-site scripting (XSS) via the keywords parameter2022-03-04
OSV
Liferay Portal vulnerable to cross-site scripting (XSS) via the keywords parameter2022-03-04
CVEList
CVE-2021-38264: Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 72022-03-02
CVE-2021-38264 — Cross-site Scripting in Liferay Portal | cvebase