Количество 2
Количество 2
CVE-2021-33336
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.
GHSA-fvg6-9r88-7w85
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-33336 Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
GHSA-fvg6-9r88-7w85 Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу