PT-2022-10704 · Liferay · Liferay Portal
Published
2022-03-02
·
Updated
2022-06-05
·
CVE-2021-38264
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.0 through 7.4.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML into the management toolbar search. This is achieved via the
keywords parameter. The issue stems from an incomplete fix.Recommendations
For Liferay Portal versions 7.4.0 and 7.4.1, avoid using the
keywords parameter in the management toolbar search until a patch is available. As a temporary workaround, consider restricting access to the management toolbar to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Portal