CVE-2021-33339: XSS
Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the comliferaysiteadminwebportletSiteAdminPortletname parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33339?
CVE-2021-33339 is a cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9, which allows remote attackers to inject arbitrary web script or HTML.
How severe is CVE-2021-33339?
CVE-2021-33339 has a severity rating of 4.8 (medium).
What is the affected software for CVE-2021-33339?
The affected software for CVE-2021-33339 includes Liferay Portal 7.2.1 through 7.3.4 and Liferay DXP 7.2 before fix pack 9.
How can I fix CVE-2021-33339?
To fix CVE-2021-33339, update your Liferay software to version 7.2-fix_pack_9 or higher.
Where can I find more information about CVE-2021-33339?
You can find more information about CVE-2021-33339 at the following references: [link1](https://issues.liferay.com/browse/LPE-17102) [link2](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747934)