CVE-2021-29045: XSS
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the comliferayredirectwebinternalportletRedirectPortletdestinationURL parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp1 - Upgrade
Upgrade
Liferay Portal / Liferay DXP Redirect module (RedirectPortlet)to a version that resolves this vulnerability.Fixed in 7.3.5Patch fix pack 1 - Upgrade
Upgrade
Liferay Portal 7.3.2-7.3.4 Redirect module (RedirectPortlet)to a version that resolves this vulnerability.Patch fix pack 1
Event History
Frequently Asked Questions
What is CVE-2021-29045?
CVE-2021-29045 is a cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1.
How does CVE-2021-29045 impact my system?
CVE-2021-29045 allows remote attackers to inject arbitrary web script or HTML.
What is the severity of CVE-2021-29045?
The severity of CVE-2021-29045 is medium with a CVSS score of 6.1 out of 10.
How can I fix CVE-2021-29045?
To mitigate CVE-2021-29045, you should apply the appropriate security patch provided by Liferay.
Where can I find more information about CVE-2021-29045?
You can find more information about CVE-2021-29045 on the Liferay website and the Liferay Developer Portal.