CVE-2021-38264
Summary
| CVE | CVE-2021-38264 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-03 00:15:00 UTC |
| Updated | 2022-06-05 03:51:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-38264 Reflected XSS with `keywords` in Search |
MISC |
portal.liferay.dev |
|
| Digital Experience Software Tailored to Your Needs | Liferay |
MISC |
liferay.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730488 Liferay Portal Reflected Cross-Site Scripting (XSS) Vulnerability