CVE-2021-33337 – com.liferay.portal:release.dxp.bom
Package
Manager: maven
Name: com.liferay.portal:release.dxp.bom
Vulnerable Version: >=7.1.0 <7.1.10.fp20 || >=7.2.0 <7.2.10.fp9
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00258 pctl0.49003
Details
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu versions 5.0.6 to before 5.0.54, in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.
Metadata
Created: 2022-05-24T19:10:00Z
Modified: 2025-07-14T17:46:41Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v88g-7fx4-9q7f/GHSA-v88g-7fx4-9q7f.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-v88g-7fx4-9q7f
Finding: F425
Auto approve: 1