PT-2022-10705 · Liferay · Liferay Portal

Published

2022-03-02

·

Updated

2024-01-31

·

CVE-2021-38265

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.3.4 through 7.3.6
Description A cross-site scripting (XSS) issue exists in the Asset module, allowing remote attackers to inject arbitrary web script or HTML when creating a collection page. This is achieved via the com liferay asset list web portlet AssetListPortlet title parameter.
Recommendations For Liferay Portal versions 7.3.4 through 7.3.6, consider restricting access to the Asset module until a patch is available. As a temporary workaround, avoid using the com liferay asset list web portlet AssetListPortlet title parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-LIFERAY-2021-38265
CVE-2021-38265
GHSA-3X83-WHXW-PVMG

Affected Products

Liferay Portal