CVE-2021-38264

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:liferay_portal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:7.4.1:-:*:*:*:*:*:*

History

15 Apr 2022, 17:15

Type Values Removed Values Added
Summary Liferay Portal v7.4.1 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the keywords parameter under the Frontend Taglib module. Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.

14 Mar 2022, 17:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
First Time Liferay liferay Portal
Liferay
CPE cpe:2.3:a:liferay:liferay_portal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:7.4.1:-:*:*:*:*:*:*
CWE CWE-79
References (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - Patch, Vendor Advisory
References (MISC) http://liferay.com - (MISC) http://liferay.com - Product

03 Mar 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-03 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-38264

Mitre link : CVE-2021-38264

CVE.ORG link : CVE-2021-38264


JSON object : View

Products Affected

liferay

  • liferay_portal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')