Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24721 | Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script console |
Github GHSA |
GHSA-ffmm-5ww2-g3q4 | Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script console |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:37:16.466Z
Reserved: 2021-08-09T00:00:00
Link: CVE-2021-38263
No data.
Status : Modified
Published: 2022-03-03T00:15:07.933
Modified: 2024-11-21T06:16:41.793
Link: CVE-2021-38263
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA