CVE-2021-29046

Description

Cross-site scripting (XSS) vulnerability in the Asset modules category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.474

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-29046,CVE-2021-29045 are fixed in Liferay - release.dxp.bom 7.3.10Windows
Vulnerabilities CVE-2021-29046 are affected in Liferay - release.portal.bom 7.3.5Windows
Vulnerabilities CVE-2021-29046,CVE-2021-29045 are fixed in Liferay - release.dxp.bom for Linux 7.3.10Linux
Vulnerabilities CVE-2021-29046 are affected in Liferay - release.portal.bom for Linux 7.3.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234