Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15685 | Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page |
Github GHSA |
GHSA-239w-4f3w-cfcv | Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:55:12.528Z
Reserved: 2021-03-22T00:00:00
Link: CVE-2021-29039
No data.
Status : Modified
Published: 2021-05-16T15:15:07.457
Modified: 2024-11-21T06:00:34.373
Link: CVE-2021-29039
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA