6.1
CVE-2022-28979
- EPSS 0.41%
- Veröffentlicht 22.09.2022 00:15:09
- Zuletzt bearbeitet 09.07.2026 01:17:26
- Erkennungen
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Parameter Name text field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version 7.1 Update -
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_1
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_10
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_11
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_12
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_13
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_14
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_15
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_16
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_17
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_18
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_19
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_2
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_20
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_21
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_22
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_23
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_24
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_25
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_3
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_4
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_5
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_6
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_7
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_8
Liferay ≫ Digital Experience Platform Version 7.1 Update fix_pack_9
Liferay ≫ Digital Experience Platform Version 7.2 Update -
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_1
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_10
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_11
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_12
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_13
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_14
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_2
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_3
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_4
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_5
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_6
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_7
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_8
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_9
Liferay ≫ Liferay Portal Version >= 7.1.0 < 7.4.3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.332 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| CISA-ADP | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://issues.liferay.com/browse/LPE-17381
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28979-xss-in-custom-facet-widget