← Back

CVE-2022-42113

nvd nist
Published: Oct 18, 2022Modified: Jul 9, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.

Affected (8)

2 products
Dxp
Liferay Portal
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update_30
Version 7.4 update_31
Version 7.4 update_32
Version 7.4 update_33
Version 7.4 update_34
Version 7.4 update_35
Version 7.4 update_36
From 7.4.3.30 to 7.4.3.37

Timeline

No history available yet.