Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2021-33336

Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.

  • Published: Aug 4, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-33336
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
liferay / liferay_portal 7.3.0 7.3.4
liferay / digital_experience_platform 7.2-fix_pack_5 7.2-fix_pack_5.x
liferay / digital_experience_platform 7.1-fix_pack_6 7.1-fix_pack_6.x
liferay / digital_experience_platform 7.1-fix_pack_9 7.1-fix_pack_9.x
liferay / digital_experience_platform 7.1-fix_pack_10 7.1-fix_pack_10.x
liferay / digital_experience_platform 7.1-fix_pack_11 7.1-fix_pack_11.x
liferay / digital_experience_platform 7.1-fix_pack_12 7.1-fix_pack_12.x
liferay / digital_experience_platform 7.1-fix_pack_7 7.1-fix_pack_7.x
liferay / digital_experience_platform 7.1-fix_pack_13 7.1-fix_pack_13.x
liferay / digital_experience_platform 7.1-fix_pack_14 7.1-fix_pack_14.x
liferay / digital_experience_platform 7.1-fix_pack_15 7.1-fix_pack_15.x
liferay / digital_experience_platform 7.1-fix_pack_16 7.1-fix_pack_16.x
liferay / digital_experience_platform 7.1-fix_pack_1 7.1-fix_pack_1.x
liferay / digital_experience_platform 7.1-fix_pack_2 7.1-fix_pack_2.x
liferay / digital_experience_platform 7.1-fix_pack_3 7.1-fix_pack_3.x
liferay / digital_experience_platform 7.1-fix_pack_4 7.1-fix_pack_4.x
liferay / digital_experience_platform 7.1-fix_pack_5 7.1-fix_pack_5.x
liferay / digital_experience_platform 7.1 7.1.x
liferay / digital_experience_platform 7.1-fix_pack_17 7.1-fix_pack_17.x
liferay / digital_experience_platform 7.1-fix_pack_8 7.1-fix_pack_8.x
liferay / digital_experience_platform 7.2-fix_pack_6 7.2-fix_pack_6.x
liferay / digital_experience_platform 7.2-fix_pack_7 7.2-fix_pack_7.x