CVE-2021-29049
Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
6.1
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the currentURL parameter.
How to fix CVE-2021-29049
To remediate CVE-2021-29049, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.10.fp99 or later
Is CVE-2021-29049 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.0, < 7.0.10.fp99
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |