5.4

CVE-2022-38901

Exploit

A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.

Data is provided by the National Vulnerability Database (NVD)
LiferayDxp Version >= 7.0 < 7.3
LiferayDxp Version7.3 Update-
LiferayDxp Version7.3 Updateupdate_1
LiferayDxp Version7.3 Updateupdate_2
LiferayDxp Version7.3 Updateupdate_3
LiferayDxp Version7.3 Updateupdate_4
LiferayDxp Version7.3 Updateupdate_5
LiferayDxp Version7.4 Updateupdate_1
LiferayDxp Version7.4 Updateupdate_10
LiferayDxp Version7.4 Updateupdate_11
LiferayDxp Version7.4 Updateupdate_12
LiferayDxp Version7.4 Updateupdate_13
LiferayDxp Version7.4 Updateupdate_14
LiferayDxp Version7.4 Updateupdate_15
LiferayDxp Version7.4 Updateupdate_16
LiferayDxp Version7.4 Updateupdate_17
LiferayDxp Version7.4 Updateupdate_18
LiferayDxp Version7.4 Updateupdate_19
LiferayDxp Version7.4 Updateupdate_2
LiferayDxp Version7.4 Updateupdate_20
LiferayDxp Version7.4 Updateupdate_21
LiferayDxp Version7.4 Updateupdate_22
LiferayDxp Version7.4 Updateupdate_23
LiferayDxp Version7.4 Updateupdate_24
LiferayDxp Version7.4 Updateupdate_25
LiferayDxp Version7.4 Updateupdate_26
LiferayDxp Version7.4 Updateupdate_27
LiferayDxp Version7.4 Updateupdate_28
LiferayDxp Version7.4 Updateupdate_3
LiferayDxp Version7.4 Updateupdate_4
LiferayDxp Version7.4 Updateupdate_5
LiferayDxp Version7.4 Updateupdate_6
LiferayDxp Version7.4 Updateupdate_7
LiferayDxp Version7.4 Updateupdate_8
LiferayDxp Version7.4 Updateupdate_9
LiferayLiferay Portal Version >= 7.3.5 <= 7.4.3.28
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.509
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.