Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-03T18:37:32

Updated: 2024-08-03T23:50:41.576Z

Reserved: 2021-05-20T00:00:00

Link: CVE-2021-33326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-03T19:15:08.757

Modified: 2021-08-11T14:44:09.970

Link: CVE-2021-33326

cve-icon Redhat

No data.