CVE-2021-35463: XSS
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the keywords parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35463?
CVE-2021-35463 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2021-35463?
To remediate CVE-2021-35463, update Liferay Portal to a version later than 7.4.0 that includes the security patch.
Who is affected by CVE-2021-35463?
CVE-2021-35463 affects users of Liferay Portal version 7.4.0 who utilize the Frontend Taglib module.
What kind of attacks can CVE-2021-35463 facilitate?
CVE-2021-35463 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
Is CVE-2021-35463 easy to exploit?
CVE-2021-35463 may be exploited by remote attackers without needing authentication, making it relatively easy to exploit.