CVE-2021-38264: XSS
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the keywords parameter. This issue is caused by an incomplete fix in CVE-2021-35463.
Other sources
Liferay Portal v7.4.1 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the keywords parameter under the Frontend Taglib module before 7.1.15.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.frontend.taglib.clayto a version that resolves this vulnerability.Fixed in 7.1.15 - Upgrade
Upgrade
Liferay Portal Frontend Taglib moduleto a version that resolves this vulnerability.Fixed in 7.1.15 - Upgrade
Upgrade
Liferay Portal 7.4.0to a version that resolves this vulnerability.Fixed in 7.1.15 - Upgrade
Upgrade
Liferay Portal 7.4.1to a version that resolves this vulnerability.Fixed in 7.1.15
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38264?
CVE-2021-38264 is classified as a cross-site scripting (XSS) vulnerability which can lead to serious security risks including data theft or session hijacking.
How do I fix CVE-2021-38264?
To remediate CVE-2021-38264, it is recommended to upgrade to Liferay Portal version 7.4.2 or later where the vulnerability has been addressed.
Who is affected by CVE-2021-38264?
CVE-2021-38264 affects users of Liferay Portal versions 7.4.0 and 7.4.1.
What causes the vulnerability CVE-2021-38264?
CVE-2021-38264 is caused by an incomplete fix from a previous vulnerability, specifically CVE-2021-35463, related to improper input validation.
What kind of threat does CVE-2021-38264 represent?
CVE-2021-38264 represents a threat where remote attackers can inject arbitrary web scripts or HTML via the management toolbar search using the 'keywords' parameter.