CVE-2021-38265: XSS
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the comliferayassetlistwebportletAssetListPortlettitle parameter.
Other sources
Liferay Layout Admin Web before 5.0.0 in Liferay Portal v7.3.6 and below and Liferay DXP v7.3 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the comliferayassetlistwebportletAssetListPortlettitle parameter.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.layout.admin.webto a version that resolves this vulnerability.Fixed in 5.0.0
Event History
Frequently Asked Questions
What is CVE-2021-38265?
CVE-2021-38265 is a cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6.
How does CVE-2021-38265 affect Liferay Portal?
CVE-2021-38265 allows remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
What is the severity of CVE-2021-38265?
The severity of CVE-2021-38265 is medium with a CVSS severity score of 5.4.
How can I fix CVE-2021-38265?
To fix CVE-2021-38265, upgrade your Liferay Portal version to 7.3.7 or later.
Where can I find more information about CVE-2021-38265?
You can find more information about CVE-2021-38265 on the official Lifery website: http://liferay.com and the Lifery Portal security advisory: https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38265-stored-xss-with-collection-name