---
id: CVE-2021-38263
title: >-
  Cross-site scripting (XSS) vulnerability in the Server module's script console
  in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101,
  7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to
  inj…
summary: >-
  Cross-site scripting (XSS) vulnerability in the Server module's script console
  in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101,
  7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to
  inj…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: liferay
product: liferay_portal
affected:
  - liferay_portal <= 7.3.2
  - digital_experience_platform = 7.0
  - digital_experience_platform = 7.1
  - digital_experience_platform = 7.2
published: '2022-03-03'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-38263'
references:
  - url: 'https://issues.liferay.com/browse/LPE-17061'
    label: cve@mitre.org
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38263-reflected-xss-with-script-page
    label: cve@mitre.org
  - url: 'http://liferay.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://issues.liferay.com/browse/LPE-17061'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38263-reflected-xss-with-script-page
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00881
epssPercentile: 0.57645
ingestedAt: '2026-07-06T17:03:23.921Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.

## Affected

- `liferay_portal <= 7.3.2`
- `digital_experience_platform = 7.0`
- `digital_experience_platform = 7.1`
- `digital_experience_platform = 7.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
