First published: Mon May 17 2021(Updated: )
Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_XXXXXXXXXXXX_assetEntryId parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay DXP | =7.1 | |
Liferay DXP | =7.1-fix_pack_1 | |
Liferay DXP | =7.1-fix_pack_10 | |
Liferay DXP | =7.1-fix_pack_11 | |
Liferay DXP | =7.1-fix_pack_12 | |
Liferay DXP | =7.1-fix_pack_13 | |
Liferay DXP | =7.1-fix_pack_14 | |
Liferay DXP | =7.1-fix_pack_15 | |
Liferay DXP | =7.1-fix_pack_16 | |
Liferay DXP | =7.1-fix_pack_17 | |
Liferay DXP | =7.1-fix_pack_18 | |
Liferay DXP | =7.1-fix_pack_19 | |
Liferay DXP | =7.1-fix_pack_2 | |
Liferay DXP | =7.1-fix_pack_20 | |
Liferay DXP | =7.1-fix_pack_3 | |
Liferay DXP | =7.1-fix_pack_4 | |
Liferay DXP | =7.1-fix_pack_5 | |
Liferay DXP | =7.1-fix_pack_6 | |
Liferay DXP | =7.1-fix_pack_7 | |
Liferay DXP | =7.1-fix_pack_8 | |
Liferay DXP | =7.1-fix_pack_9 | |
Liferay DXP | =7.2 | |
Liferay DXP | =7.2-fix_pack_1 | |
Liferay DXP | =7.2-fix_pack_2 | |
Liferay DXP | =7.2-fix_pack_3 | |
Liferay DXP | =7.2-fix_pack_4 | |
Liferay DXP | =7.2-fix_pack_5 | |
Liferay DXP | =7.2-fix_pack_6 | |
Liferay DXP | =7.2-fix_pack_7 | |
Liferay DXP | =7.2-fix_pack_8 | |
Liferay DXP | =7.2-fix_pack_9 | |
Liferay DXP | =7.3 | |
Liferay Liferay Portal | >=7.2.0<=7.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29051 is medium.
CVE-2021-29051 affects Liferay Portal versions 7.2.1 through 7.3.5, and Liferay DXP versions 7.1 before fix pack 21, 7.2 before fix pack 10, and 7.3 before fix pack 1.
The vulnerability in CVE-2021-29051 is a cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app.
CVE-2021-29051 can be exploited by remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset parameter.
More information about CVE-2021-29051 can be found at the following references: [http://liferay.com](http://liferay.com), [https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743580](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743580)