CVE-2021-38263
03.03.2022, 00:15
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
| Vendor | Product | Version |
|---|---|---|
| liferay | liferay_portal | 𝑥 ≤ 7.3.2 |
| liferay | digital_experience_platform | 7.0 |
| liferay | digital_experience_platform | 7.0:fix_pack_1 |
| liferay | digital_experience_platform | 7.0:fix_pack_10 |
| liferay | digital_experience_platform | 7.0:fix_pack_100 |
| liferay | digital_experience_platform | 7.0:fix_pack_11 |
| liferay | digital_experience_platform | 7.0:fix_pack_12 |
| liferay | digital_experience_platform | 7.0:fix_pack_13 |
| liferay | digital_experience_platform | 7.0:fix_pack_14 |
| liferay | digital_experience_platform | 7.0:fix_pack_15 |
| liferay | digital_experience_platform | 7.0:fix_pack_16 |
| liferay | digital_experience_platform | 7.0:fix_pack_17 |
| liferay | digital_experience_platform | 7.0:fix_pack_18 |
| liferay | digital_experience_platform | 7.0:fix_pack_19 |
| liferay | digital_experience_platform | 7.0:fix_pack_2 |
| liferay | digital_experience_platform | 7.0:fix_pack_20 |
| liferay | digital_experience_platform | 7.0:fix_pack_21 |
| liferay | digital_experience_platform | 7.0:fix_pack_22 |
| liferay | digital_experience_platform | 7.0:fix_pack_23 |
| liferay | digital_experience_platform | 7.0:fix_pack_24 |
| liferay | digital_experience_platform | 7.0:fix_pack_25 |
| liferay | digital_experience_platform | 7.0:fix_pack_26 |
| liferay | digital_experience_platform | 7.0:fix_pack_27 |
| liferay | digital_experience_platform | 7.0:fix_pack_28 |
| liferay | digital_experience_platform | 7.0:fix_pack_29 |
| liferay | digital_experience_platform | 7.0:fix_pack_3 |
| liferay | digital_experience_platform | 7.0:fix_pack_30 |
| liferay | digital_experience_platform | 7.0:fix_pack_31 |
| liferay | digital_experience_platform | 7.0:fix_pack_32 |
| liferay | digital_experience_platform | 7.0:fix_pack_33 |
| liferay | digital_experience_platform | 7.0:fix_pack_34 |
| liferay | digital_experience_platform | 7.0:fix_pack_35 |
| liferay | digital_experience_platform | 7.0:fix_pack_36 |
| liferay | digital_experience_platform | 7.0:fix_pack_37 |
| liferay | digital_experience_platform | 7.0:fix_pack_38 |
| liferay | digital_experience_platform | 7.0:fix_pack_39 |
| liferay | digital_experience_platform | 7.0:fix_pack_4 |
| liferay | digital_experience_platform | 7.0:fix_pack_40 |
| liferay | digital_experience_platform | 7.0:fix_pack_41 |
| liferay | digital_experience_platform | 7.0:fix_pack_42 |
| liferay | digital_experience_platform | 7.0:fix_pack_43 |
| liferay | digital_experience_platform | 7.0:fix_pack_44 |
| liferay | digital_experience_platform | 7.0:fix_pack_45 |
| liferay | digital_experience_platform | 7.0:fix_pack_46 |
| liferay | digital_experience_platform | 7.0:fix_pack_47 |
| liferay | digital_experience_platform | 7.0:fix_pack_48 |
| liferay | digital_experience_platform | 7.0:fix_pack_49 |
| liferay | digital_experience_platform | 7.0:fix_pack_5 |
| liferay | digital_experience_platform | 7.0:fix_pack_50 |
| liferay | digital_experience_platform | 7.0:fix_pack_51 |
| liferay | digital_experience_platform | 7.0:fix_pack_52 |
| liferay | digital_experience_platform | 7.0:fix_pack_53 |
| liferay | digital_experience_platform | 7.0:fix_pack_54 |
| liferay | digital_experience_platform | 7.0:fix_pack_55 |
| liferay | digital_experience_platform | 7.0:fix_pack_56 |
| liferay | digital_experience_platform | 7.0:fix_pack_57 |
| liferay | digital_experience_platform | 7.0:fix_pack_58 |
| liferay | digital_experience_platform | 7.0:fix_pack_59 |
| liferay | digital_experience_platform | 7.0:fix_pack_6 |
| liferay | digital_experience_platform | 7.0:fix_pack_60 |
| liferay | digital_experience_platform | 7.0:fix_pack_61 |
| liferay | digital_experience_platform | 7.0:fix_pack_62 |
| liferay | digital_experience_platform | 7.0:fix_pack_63 |
| liferay | digital_experience_platform | 7.0:fix_pack_64 |
| liferay | digital_experience_platform | 7.0:fix_pack_65 |
| liferay | digital_experience_platform | 7.0:fix_pack_66 |
| liferay | digital_experience_platform | 7.0:fix_pack_67 |
| liferay | digital_experience_platform | 7.0:fix_pack_68 |
| liferay | digital_experience_platform | 7.0:fix_pack_69 |
| liferay | digital_experience_platform | 7.0:fix_pack_7 |
| liferay | digital_experience_platform | 7.0:fix_pack_70 |
| liferay | digital_experience_platform | 7.0:fix_pack_71 |
| liferay | digital_experience_platform | 7.0:fix_pack_72 |
| liferay | digital_experience_platform | 7.0:fix_pack_73 |
| liferay | digital_experience_platform | 7.0:fix_pack_74 |
| liferay | digital_experience_platform | 7.0:fix_pack_75 |
| liferay | digital_experience_platform | 7.0:fix_pack_76 |
| liferay | digital_experience_platform | 7.0:fix_pack_77 |
| liferay | digital_experience_platform | 7.0:fix_pack_78 |
| liferay | digital_experience_platform | 7.0:fix_pack_79 |
| liferay | digital_experience_platform | 7.0:fix_pack_8 |
| liferay | digital_experience_platform | 7.0:fix_pack_80 |
| liferay | digital_experience_platform | 7.0:fix_pack_81 |
| liferay | digital_experience_platform | 7.0:fix_pack_82 |
| liferay | digital_experience_platform | 7.0:fix_pack_83 |
| liferay | digital_experience_platform | 7.0:fix_pack_84 |
| liferay | digital_experience_platform | 7.0:fix_pack_85 |
| liferay | digital_experience_platform | 7.0:fix_pack_86 |
| liferay | digital_experience_platform | 7.0:fix_pack_87 |
| liferay | digital_experience_platform | 7.0:fix_pack_88 |
| liferay | digital_experience_platform | 7.0:fix_pack_89 |
| liferay | digital_experience_platform | 7.0:fix_pack_9 |
| liferay | digital_experience_platform | 7.0:fix_pack_90 |
| liferay | digital_experience_platform | 7.0:fix_pack_91 |
| liferay | digital_experience_platform | 7.0:fix_pack_92 |
| liferay | digital_experience_platform | 7.0:fix_pack_93 |
| liferay | digital_experience_platform | 7.0:fix_pack_94 |
| liferay | digital_experience_platform | 7.0:fix_pack_95 |
| liferay | digital_experience_platform | 7.0:fix_pack_96 |
| liferay | digital_experience_platform | 7.0:fix_pack_97 |
| liferay | digital_experience_platform | 7.0:fix_pack_98 |
| liferay | digital_experience_platform | 7.0:fix_pack_99 |
| liferay | digital_experience_platform | 7.1 |
| liferay | digital_experience_platform | 7.1:fix_pack_1 |
| liferay | digital_experience_platform | 7.1:fix_pack_10 |
| liferay | digital_experience_platform | 7.1:fix_pack_11 |
| liferay | digital_experience_platform | 7.1:fix_pack_12 |
| liferay | digital_experience_platform | 7.1:fix_pack_13 |
| liferay | digital_experience_platform | 7.1:fix_pack_14 |
| liferay | digital_experience_platform | 7.1:fix_pack_15 |
| liferay | digital_experience_platform | 7.1:fix_pack_16 |
| liferay | digital_experience_platform | 7.1:fix_pack_17 |
| liferay | digital_experience_platform | 7.1:fix_pack_18 |
| liferay | digital_experience_platform | 7.1:fix_pack_19 |
| liferay | digital_experience_platform | 7.1:fix_pack_2 |
| liferay | digital_experience_platform | 7.1:fix_pack_3 |
| liferay | digital_experience_platform | 7.1:fix_pack_4 |
| liferay | digital_experience_platform | 7.1:fix_pack_5 |
| liferay | digital_experience_platform | 7.1:fix_pack_6 |
| liferay | digital_experience_platform | 7.1:fix_pack_7 |
| liferay | digital_experience_platform | 7.1:fix_pack_8 |
| liferay | digital_experience_platform | 7.1:fix_pack_9 |
| liferay | digital_experience_platform | 7.2 |
| liferay | digital_experience_platform | 7.2:fix_pack_1 |
| liferay | digital_experience_platform | 7.2:fix_pack_2 |
| liferay | digital_experience_platform | 7.2:fix_pack_3 |
| liferay | digital_experience_platform | 7.2:fix_pack_4 |
| liferay | digital_experience_platform | 7.2:fix_pack_5 |
| liferay | digital_experience_platform | 7.2:fix_pack_6 |
| liferay | digital_experience_platform | 7.2:fix_pack_7 |
| liferay | digital_experience_platform | 7.2:fix_pack_8 |
| liferay | digital_experience_platform | 7.2:fix_pack_9 |
𝑥
= Vulnerable software versions
References