Vulnerability Details CVE-2021-33331
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2021-33331
-
cpe:2.3:a:liferay:dxp:7.0
-
cpe:2.3:a:liferay:dxp:7.1
-
cpe:2.3:a:liferay:dxp:7.2
-
cpe:2.3:a:liferay:liferay_portal:7.0.0
-
cpe:2.3:a:liferay:liferay_portal:7.0.1
-
cpe:2.3:a:liferay:liferay_portal:7.0.2
-
cpe:2.3:a:liferay:liferay_portal:7.0.3
-
cpe:2.3:a:liferay:liferay_portal:7.0.3_ga4
-
cpe:2.3:a:liferay:liferay_portal:7.0.4
-
cpe:2.3:a:liferay:liferay_portal:7.0.5
-
cpe:2.3:a:liferay:liferay_portal:7.0.6
-
cpe:2.3:a:liferay:liferay_portal:7.1
-
cpe:2.3:a:liferay:liferay_portal:7.1.0
-
cpe:2.3:a:liferay:liferay_portal:7.1.1
-
cpe:2.3:a:liferay:liferay_portal:7.1.2
-
cpe:2.3:a:liferay:liferay_portal:7.1.3
-
cpe:2.3:a:liferay:liferay_portal:7.2
-
cpe:2.3:a:liferay:liferay_portal:7.2.0
-
cpe:2.3:a:liferay:liferay_portal:7.2.1
-
cpe:2.3:a:liferay:liferay_portal:7.3
-
cpe:2.3:a:liferay:liferay_portal:7.3.0
-
cpe:2.3:a:liferay:liferay_portal:7.3.1