Description
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_web_portlet_MySitesPortlet_comments parameter.
Published: 2021-05-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-15690 Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
Github GHSA Github GHSA GHSA-wcr5-3q96-c2gr Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
History

Tue, 13 May 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Liferay digital Experience Platform
CPEs cpe:2.3:a:liferay:dxp:7.0:-:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_24:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_25:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_26:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_27:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_28:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_30:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_33:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_35:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_36:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_39:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_3\+:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_40:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_41:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_42:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_43:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_44:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_45:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_46:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_47:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_48:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_49:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_50:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_51:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_52:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_53:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_54:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_56:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_57:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_58:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_59:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_60:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_61:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_64:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_65:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_66:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_67:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_68:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_69:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_70:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_71:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_72:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_73:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_75:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_76:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_78:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_79:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_80:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_81:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_82:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_83:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_84:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_85:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_86:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_87:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_88:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_89:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_90:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_91:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_92:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_93:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_94:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_95:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_96:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_10:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_11:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_12:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_15:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_16:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_17:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_18:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_19:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_20:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_6:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_7:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_8:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_9:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:-:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_6:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_7:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_8:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_9:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_24:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_25:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_26:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_27:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_28:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_30:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_33:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_35:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_36:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_39:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_40:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_41:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_42:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_43:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_44:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_45:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_46:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_47:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_48:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_49:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_50:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_51:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_52:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_53:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_54:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_56:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_57:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_58:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_59:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_60:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_61:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_64:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_65:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_66:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_67:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_68:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_69:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_70:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_71:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_72:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_73:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_75:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_76:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_78:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_79:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_80:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_81:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_82:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_83:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_84:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_85:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_86:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_87:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_88:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_89:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_90:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_91:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_92:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_93:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_94:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_95:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_96:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_10:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_11:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_12:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_15:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_16:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_17:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_18:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_19:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_20:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_6:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_7:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_8:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_9:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_6:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_7:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_8:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_9:*:*:*:*:*:*
Vendors & Products Liferay digital Experience Platform

Subscriptions

Liferay Digital Experience Platform Dxp Liferay Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T21:55:12.632Z

Reserved: 2021-03-22T00:00:00.000Z

Link: CVE-2021-29044

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-17T11:15:07.210

Modified: 2025-05-13T18:17:51.450

Link: CVE-2021-29044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses