← Back

CVE-2022-42119

nvd nist
Published: Nov 15, 2022Modified: Jul 9, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

Affected (9)

2 products
Liferay Portal
Dxp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.3.5 to 7.4.2
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.3
Version 7.3 update_1
Version 7.3 update_2
Version 7.3 update_3
Version 7.3 update_4
Version 7.3 update_5
Version 7.3 update_6
Version 7.3 update_7

References (4)

Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.