← Back

CVE-2022-42120

nvd nist
Published: Nov 15, 2022Modified: Sep 5, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

Affected (3)

2 products
Dxp
Liferay Portal
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.3
Version 7.4
From 7.3.3 to 7.4.3.16

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.