CVE-2021-29039
Description
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Liferay Portal's Asset module categories page via site name.
Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in the Asset module's categories administration page in Liferay Portal 7.3.4 [1][2][4]. The issue allows remote attackers to inject arbitrary web script or HTML via the site name field [1][4]. The vulnerability is specifically in the categories administration page of the Asset module, where the site name is not properly sanitized before being displayed [1][4]. Affected versions include Liferay Portal 7.3.4 [1][4].
Exploitation
An attacker needs network access to the Liferay Portal instance and sufficient permissions to access the Asset module's categories administration page [1][4]. The attacker can inject malicious script or HTML into the site name field, which is then stored and subsequently executed when the categories administration page is rendered for other users [1][4]. No user interaction beyond viewing the affected page is required for successful exploitation [1][4].
Impact
Successful exploitation allows an attacker to execute arbitrary web script or HTML in the context of the victim's browser session [1][4]. This can lead to information disclosure, session hijacking, or other malicious activities that the injected script can perform [1][4]. The impact is limited to the browser session of users who view the affected categories page [1][4].
Mitigation
Liferay Portal 7.3.4 has no patch available [4]. Users should upgrade to Liferay Portal CE 7.3 GA6 (7.3.5) or later to remediate the vulnerability [4]. No other workaround is disclosed in the available references [1][2][3][4].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | >= 7.3.4, < 7.3.5 | 7.3.5 |
Affected products
2- Liferay/Liferay Portaldescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-239w-4f3w-cfcvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-29039ghsaADVISORY
- liferay.comghsax_refsource_MISCWEB
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120777766mitrex_refsource_MISC
- web.archive.org/web/20220828222833/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120777766ghsaWEB
News mentions
0No linked articles in our index yet.