MEDIUM
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter
Published Aug 4, 2021
6.1
MEDIUMCVSS 3.1
EPSS 0.80%
Description
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.
Affected products
No data.
OR
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- ≥ 7.3.0 · ≤ 7.3.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-20045 Advisory
- https://github.com/advisories/GHSA-v88g-7fx4-9q7f Advisory
- https://github.com/liferay/liferay-portal/commit/432e9eb911d11ff40e1db652690586e496940633
- https://issues.liferay.com/browse/LPE-17101 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2021-33337
- https://nvd.nist.gov/vuln/detail/CVE-2021-33337
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-33337-stored-xss-with-document-types-in-documents-and-media x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 4, 2021
Updated Aug 3, 2024
Reserved May 20, 2021
Link CVE-2021-33337
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-20045 GHSA-V88G-7FX4-9Q7F Assigner mitre
Published Aug 4, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-20045