CVE-2021-38267: XSS
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the comliferayblogswebportletBlogsAdminPortlettitle and comliferayblogswebportletBlogsAdminPortletsubtitle parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.frontend.js.webto a version that resolves this vulnerability.Fixed in 5.0.0 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp2 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.7-ga8 - Upgrade
Upgrade
Liferay Portal / Liferay DXP Blogs moduleto a version that resolves this vulnerability.Fixed in 7.3.6 - Upgrade
Upgrade
Liferay Portal / Liferay DXPto a version that resolves this vulnerability.Patch fix pack 2
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38267?
The severity of CVE-2021-38267 is medium with a CVSS score of 5.4.
How does CVE-2021-38267 affect Liferay Digital Experience Platform?
CVE-2021-38267 affects Liferay Digital Experience Platform 7.3, 7.3-fix_pack_1, and 7.3.0 through 7.3.6.
What is the impact of CVE-2021-38267?
CVE-2021-38267 allows remote attackers to inject arbitrary web script or HTML via the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6 and Liferay DXP 7.3 before fix pack 2.
How can I fix CVE-2021-38267?
Apply the necessary security fixes or patches provided by Liferay to mitigate CVE-2021-38267.
Where can I find more information about CVE-2021-38267?
You can find more information about CVE-2021-38267 on the Liferay website and the Liferay Developer Portal.