CVE-2021-29039: XSS
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.5
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29039?
CVE-2021-29039 is classified as a medium severity vulnerability.
How do I fix CVE-2021-29039?
To fix CVE-2021-29039, upgrade Liferay Portal to version 7.4 or later to mitigate the XSS vulnerability.
What type of vulnerability is CVE-2021-29039?
CVE-2021-29039 is a cross-site scripting (XSS) vulnerability.
What component in Liferay is affected by CVE-2021-29039?
CVE-2021-29039 affects the Asset module's categories administration page in Liferay Portal.
Who can exploit CVE-2021-29039?
Remote attackers can exploit CVE-2021-29039 to inject arbitrary web script or HTML via the site name.