CVE-2021-38265

MEDIUM5.4EPSS 0.18%

Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS)

發布日:2022/3/4修改日:2025/7/14
也稱為:GHSA-3x83-whxw-pvmgBIT-liferay-2021-38265

描述

Liferay Layout Admin Web before 5.0.0 in Liferay Portal v7.3.6 and below and Liferay DXP v7.3 and below were discovered to contain a cross-site scripting (XSS) vulnerability via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(7)