Количество 2
Количество 2
CVE-2021-38267
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle parameter.
GHSA-r39x-3qq4-gxmr
Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in edit blog entry page
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-38267 Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle parameter. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-r39x-3qq4-gxmr Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in edit blog entry page | CVSS3: 5.4 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу