CVE-2021-33337: XSS
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the comliferaydocumentlibrarywebportletDLAdminPortletname parameter.
Other sources
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu versions 5.0.6 to before 5.0.54, in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the comliferaydocumentlibrarywebportletDLAdminPortletname parameter.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33337?
CVE-2021-33337 is a cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal and Liferay DXP.
How does CVE-2021-33337 affect Liferay Portal?
CVE-2021-33337 affects Liferay Portal versions 7.3.0 through 7.3.4.
How does CVE-2021-33337 affect Liferay DXP?
CVE-2021-33337 affects Liferay DXP versions 7.1 before fix pack 20, and 7.2 before fix pack 9.
What is the severity of CVE-2021-33337?
CVE-2021-33337 has a severity keyword of medium and a severity value of 6.1.
How can I fix CVE-2021-33337?
To fix CVE-2021-33337, you should update to the latest version of Liferay Portal or Liferay DXP that includes the fix pack.