CVE-2021-38269 — Cross-site Scripting in Portal
Severity
5.4MEDIUMNVD
EPSS
0.2%
top 60.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateMar 4
Description
Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell module↗2022-03-04
OSV▶
Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell module↗2022-03-04
CVEList▶
CVE-2021-38269: Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7↗2022-03-02