Описание
Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script console
Liferay Server Admin Web before 4.0.12 from Liferay Portal v7.3.2 and below and Liferay DXP v7.0 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the script console under the Server module.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-38263
- https://github.com/liferay/liferay-portal/commit/1abb1bfc96242065f97c2828a02350ea2174f5f6
- https://github.com/liferay/liferay-portal/commit/771d99805b7ca69fecfcf67be5e24f2c1af1d0bb
- https://issues.liferay.com/browse/LPE-17061
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2021-38263-reflected-xss-with-script-page?p_r_p_assetEntryId=121611737&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121611737%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse
- http://liferay.com
Пакеты
Наименование
com.liferay:com.liferay.server.admin.web
maven
Затронутые версииВерсия исправления
< 4.0.12
4.0.12
Наименование
com.liferay.portal:release.dxp.bom
maven
Затронутые версииВерсия исправления
<= 7.0
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
почти 4 года назад
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.