CVE-2021-33328 – com.liferay.portal:release.dxp.bom
Package
Manager: maven
Name: com.liferay.portal:release.dxp.bom
Vulnerable Version: >=7.0.10.fp0 <7.0.10.fp96 || >=7.1.0 <7.1.10.fp20 || >=7.2.0 <7.2.10.fp9
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00148 pctl0.35884
Details
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.
Metadata
Created: 2022-05-24T19:09:46Z
Modified: 2025-05-14T07:50:44Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vpvm-3wfw-5f5c/GHSA-vpvm-3wfw-5f5c.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-vpvm-3wfw-5f5c
Finding: F425
Auto approve: 1