CVE-2021-38264

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:liferay_portal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:7.4.1:-:*:*:*:*:*:*

History

21 Nov 2024, 06:16

Type Values Removed Values Added
References () http://liferay.com - Product () http://liferay.com - Product
References () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - Patch, Vendor Advisory () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - Patch, Vendor Advisory

15 Apr 2022, 17:15

Type Values Removed Values Added
Summary Liferay Portal v7.4.1 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the keywords parameter under the Frontend Taglib module. Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.

14 Mar 2022, 17:19

Type Values Removed Values Added
CWE CWE-79
References (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search - Patch, Vendor Advisory
References (MISC) http://liferay.com - (MISC) http://liferay.com - Product
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:liferay:liferay_portal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:7.4.1:-:*:*:*:*:*:*

03 Mar 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-03 00:15

Updated : 2024-11-21 06:16


NVD link : CVE-2021-38264

Mitre link : CVE-2021-38264

CVE.ORG link : CVE-2021-38264


JSON object : View

Products Affected

liferay

  • liferay_portal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')