CVE-2021-38269Cross-site Scripting in Portal

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 60.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateMar 4

Description

Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDliferay/liferay_portal7.1.07.3.6+1

Patches

🔴Vulnerability Details

3
GHSA
Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell module2022-03-04
OSV
Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell module2022-03-04
CVEList
CVE-2021-38269: Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 72022-03-02
CVE-2021-38269 — Cross-site Scripting in Liferay Portal | cvebase