6.1

CVE-2021-29049

Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the currentURL parameter.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.0 Update-
LiferayDigital Experience Platform Version7.0 Updatefix_pack_13
LiferayDigital Experience Platform Version7.0 Updatefix_pack_14
LiferayDigital Experience Platform Version7.0 Updatefix_pack_24
LiferayDigital Experience Platform Version7.0 Updatefix_pack_25
LiferayDigital Experience Platform Version7.0 Updatefix_pack_26
LiferayDigital Experience Platform Version7.0 Updatefix_pack_27
LiferayDigital Experience Platform Version7.0 Updatefix_pack_28
LiferayDigital Experience Platform Version7.0 Updatefix_pack_3
LiferayDigital Experience Platform Version7.0 Updatefix_pack_30
LiferayDigital Experience Platform Version7.0 Updatefix_pack_33
LiferayDigital Experience Platform Version7.0 Updatefix_pack_35
LiferayDigital Experience Platform Version7.0 Updatefix_pack_36
LiferayDigital Experience Platform Version7.0 Updatefix_pack_39
LiferayDigital Experience Platform Version7.0 Updatefix_pack_40
LiferayDigital Experience Platform Version7.0 Updatefix_pack_41
LiferayDigital Experience Platform Version7.0 Updatefix_pack_42
LiferayDigital Experience Platform Version7.0 Updatefix_pack_43
LiferayDigital Experience Platform Version7.0 Updatefix_pack_44
LiferayDigital Experience Platform Version7.0 Updatefix_pack_45
LiferayDigital Experience Platform Version7.0 Updatefix_pack_46
LiferayDigital Experience Platform Version7.0 Updatefix_pack_47
LiferayDigital Experience Platform Version7.0 Updatefix_pack_48
LiferayDigital Experience Platform Version7.0 Updatefix_pack_49
LiferayDigital Experience Platform Version7.0 Updatefix_pack_50
LiferayDigital Experience Platform Version7.0 Updatefix_pack_51
LiferayDigital Experience Platform Version7.0 Updatefix_pack_52
LiferayDigital Experience Platform Version7.0 Updatefix_pack_53
LiferayDigital Experience Platform Version7.0 Updatefix_pack_54
LiferayDigital Experience Platform Version7.0 Updatefix_pack_56
LiferayDigital Experience Platform Version7.0 Updatefix_pack_57
LiferayDigital Experience Platform Version7.0 Updatefix_pack_58
LiferayDigital Experience Platform Version7.0 Updatefix_pack_59
LiferayDigital Experience Platform Version7.0 Updatefix_pack_60
LiferayDigital Experience Platform Version7.0 Updatefix_pack_61
LiferayDigital Experience Platform Version7.0 Updatefix_pack_64
LiferayDigital Experience Platform Version7.0 Updatefix_pack_65
LiferayDigital Experience Platform Version7.0 Updatefix_pack_66
LiferayDigital Experience Platform Version7.0 Updatefix_pack_67
LiferayDigital Experience Platform Version7.0 Updatefix_pack_68
LiferayDigital Experience Platform Version7.0 Updatefix_pack_69
LiferayDigital Experience Platform Version7.0 Updatefix_pack_70
LiferayDigital Experience Platform Version7.0 Updatefix_pack_71
LiferayDigital Experience Platform Version7.0 Updatefix_pack_72
LiferayDigital Experience Platform Version7.0 Updatefix_pack_73
LiferayDigital Experience Platform Version7.0 Updatefix_pack_75
LiferayDigital Experience Platform Version7.0 Updatefix_pack_76
LiferayDigital Experience Platform Version7.0 Updatefix_pack_78
LiferayDigital Experience Platform Version7.0 Updatefix_pack_79
LiferayDigital Experience Platform Version7.0 Updatefix_pack_80
LiferayDigital Experience Platform Version7.0 Updatefix_pack_81
LiferayDigital Experience Platform Version7.0 Updatefix_pack_82
LiferayDigital Experience Platform Version7.0 Updatefix_pack_83
LiferayDigital Experience Platform Version7.0 Updatefix_pack_84
LiferayDigital Experience Platform Version7.0 Updatefix_pack_85
LiferayDigital Experience Platform Version7.0 Updatefix_pack_86
LiferayDigital Experience Platform Version7.0 Updatefix_pack_87
LiferayDigital Experience Platform Version7.0 Updatefix_pack_88
LiferayDigital Experience Platform Version7.0 Updatefix_pack_89
LiferayDigital Experience Platform Version7.0 Updatefix_pack_90
LiferayDigital Experience Platform Version7.0 Updatefix_pack_91
LiferayDigital Experience Platform Version7.0 Updatefix_pack_92
LiferayDigital Experience Platform Version7.0 Updatefix_pack_93
LiferayDigital Experience Platform Version7.0 Updatefix_pack_94
LiferayDigital Experience Platform Version7.0 Updatefix_pack_95
LiferayDigital Experience Platform Version7.0 Updatefix_pack_96
LiferayDigital Experience Platform Version7.0 Updatesp2
LiferayDigital Experience Platform Version7.0 Updatesp5
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_1
LiferayDigital Experience Platform Version7.1 Updatefix_pack_10
LiferayDigital Experience Platform Version7.1 Updatefix_pack_11
LiferayDigital Experience Platform Version7.1 Updatefix_pack_12
LiferayDigital Experience Platform Version7.1 Updatefix_pack_13
LiferayDigital Experience Platform Version7.1 Updatefix_pack_14
LiferayDigital Experience Platform Version7.1 Updatefix_pack_15
LiferayDigital Experience Platform Version7.1 Updatefix_pack_16
LiferayDigital Experience Platform Version7.1 Updatefix_pack_17
LiferayDigital Experience Platform Version7.1 Updatefix_pack_18
LiferayDigital Experience Platform Version7.1 Updatefix_pack_19
LiferayDigital Experience Platform Version7.1 Updatefix_pack_2
LiferayDigital Experience Platform Version7.1 Updatefix_pack_20
LiferayDigital Experience Platform Version7.1 Updatefix_pack_21
LiferayDigital Experience Platform Version7.1 Updatefix_pack_22
LiferayDigital Experience Platform Version7.1 Updatefix_pack_3
LiferayDigital Experience Platform Version7.1 Updatefix_pack_4
LiferayDigital Experience Platform Version7.1 Updatefix_pack_5
LiferayDigital Experience Platform Version7.1 Updatefix_pack_6
LiferayDigital Experience Platform Version7.1 Updatefix_pack_7
LiferayDigital Experience Platform Version7.1 Updatefix_pack_8
LiferayDigital Experience Platform Version7.1 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDxp Version7.3 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.482
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.