CVE-2022-42121
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
Affected (48)
Products: Liferay: Liferay Portal, Digital Experience Platform, Dxp
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.1.3 to 7.4.3.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 | |
| Version 7.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.1.0 to 7.4.2 |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.