CVE-2021-29046

MEDIUM

Liferay DXP 7.3.5 and 7.3 < fp1 - Cross-Site Scripting via Asset Category Selector Title Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0047
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
com.liferay.portal/release.dxp.bom 7.3.10.fp0 - 7.3.10.fp1Maven
com.liferay.portal/release.portal.bom Maven
liferay/dxp 7.3
liferay/liferay_portal 7.3.5
Published May 17, 2021
Tracked Since Feb 18, 2026