{"id":"GHSA-9h7f-5hc8-cj5f","summary":"Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module","details":"Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.","aliases":["CVE-2021-35463"],"modified":"2025-07-15T18:01:02.668860Z","published":"2022-05-24T19:10:00Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-07-14T17:37:15Z","nvd_published_at":"2021-08-04T14:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35463"},{"type":"WEB","url":"https://github.com/liferay/liferay-portal/commit/751a70e0ed7b380ea2ab510ff79ddb33ed87dd9b"},{"type":"PACKAGE","url":"https://github.com/liferay/liferay-portal"},{"type":"WEB","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2021-35463-reflected-xss-with-keywords-in-search?p_r_p_assetEntryId=121611661&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121611661%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse"}],"affected":[{"package":{"name":"com.liferay.portal:release.portal.bom","ecosystem":"Maven","purl":"pkg:maven/com.liferay.portal/release.portal.bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.4.0"},{"fixed":"7.4.1"}]}],"versions":["7.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9h7f-5hc8-cj5f/GHSA-9h7f-5hc8-cj5f.json"}},{"package":{"name":"com.liferay:com.liferay.frontend.taglib.clay","ecosystem":"Maven","purl":"pkg:maven/com.liferay/com.liferay.frontend.taglib.clay"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.15"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.3.0","1.3.1","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.13","1.4.14","1.4.15","1.4.16","1.4.17","1.4.18","1.4.19","1.4.2","1.4.20","1.4.21","1.4.22","1.4.23","1.4.24","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.21","2.2.22","2.2.23","2.2.24","2.2.25","2.2.26","2.2.27","2.2.28","2.2.29","2.2.3","2.2.30","2.2.31","2.2.32","2.2.33","2.2.34","2.2.35","2.2.36","2.2.37","2.2.38","2.2.39","2.2.4","2.2.40","2.2.41","2.2.42","2.2.43","2.2.44","2.2.45","2.2.46","2.2.47","2.2.48","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.5.0","4.0.0","4.0.1","4.0.2","4.0.3","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5","6.1.0","6.1.1","6.1.2","6.2.0","6.2.1","6.2.2","6.2.3","6.2.4","6.2.5","6.2.6","6.2.7","6.3.0","6.3.1","6.3.10","6.3.11","6.3.12","6.3.13","6.3.14","6.3.15","6.3.16","6.3.17","6.3.18","6.3.19","6.3.2","6.3.20","6.3.21","6.3.22","6.3.3","6.3.4","6.3.5","6.3.6","6.3.7","6.3.8","6.3.9","6.4.0","6.4.1","6.4.10","6.4.2","6.4.3","6.4.4","6.4.5","6.4.6","6.4.7","6.4.8","6.4.9","6.5.0","6.5.1","6.6.0","6.6.1","6.6.10","6.6.11","6.6.12","6.6.13","6.6.14","6.6.15","6.6.16","6.6.17","6.6.18","6.6.19","6.6.2","6.6.20","6.6.21","6.6.22","6.6.23","6.6.24","6.6.25","6.6.26","6.6.3","6.6.4","6.6.5","6.6.6","6.6.7","6.6.8","6.6.9","7.1.0","7.1.1","7.1.10","7.1.11","7.1.12","7.1.13","7.1.14","7.1.2","7.1.3","7.1.4","7.1.5","7.1.6","7.1.7","7.1.8","7.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9h7f-5hc8-cj5f/GHSA-9h7f-5hc8-cj5f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}