---
id: CVE-2021-29046
title: >-
  Cross-site scripting (XSS) vulnerability in the Asset module's category
  selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix
  pack 1, allows remote attackers to inject arbitrary web script or HTML via the
  _com_lifer…
summary: >-
  Cross-site scripting (XSS) vulnerability in the Asset module's category
  selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix
  pack 1, allows remote attackers to inject arbitrary web script or HTML via the
  _com_lifer…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: liferay
product: dxp
affected:
  - dxp = 7.3
  - liferay_portal = 7.3.5
published: '2021-05-17'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-29046'
references:
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743501
    label: cve@mitre.org
  - url: 'http://liferay.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743501
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0088
epssPercentile: 0.57389
ingestedAt: '2026-07-06T01:08:16.641Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.

## Affected

- `dxp = 7.3`
- `liferay_portal = 7.3.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
