CVE-2021-33336: XSS
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the comliferayjournalwebportletJournalPortletname parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33336?
CVE-2021-33336 is a cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal and Liferay DXP.
How severe is CVE-2021-33336?
CVE-2021-33336 has a severity rating of medium with a score of 5.4.
Which software versions are affected by CVE-2021-33336?
CVE-2021-33336 affects Liferay Portal 7.3.0 through 7.3.3, Liferay DXP 7.1 fix pack 18, and Liferay DXP 7.2 fix pack 5 through 7.
How can remote attackers exploit CVE-2021-33336?
Remote attackers can exploit CVE-2021-33336 by injecting arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_structureName parameter.
Where can I find more information about CVE-2021-33336?
You can find more information about CVE-2021-33336 at the following references: [Liferay issue tracker](https://issues.liferay.com/browse/LPE-17078) and [Liferay Portal Security Advisories](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-33336-stored-xss-with-structure-name).