6.1

CVE-2022-42116

A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDxp Version < 7.3
LiferayDxp Version7.3 Update-
LiferayDxp Version7.3 Updatesp1
LiferayDxp Version7.3 Updatesp2
LiferayDxp Version7.3 Updatesp3
LiferayDxp Version7.3 Updateupdate_1
LiferayDxp Version7.3 Updateupdate_2
LiferayDxp Version7.3 Updateupdate_3
LiferayDxp Version7.3 Updateupdate_4
LiferayDxp Version7.3 Updateupdate_5
LiferayDxp Version7.4 Updatega1
LiferayDxp Version7.4 Updateupdate_1
LiferayDxp Version7.4 Updateupdate_10
LiferayDxp Version7.4 Updateupdate_11
LiferayDxp Version7.4 Updateupdate_12
LiferayDxp Version7.4 Updateupdate_13
LiferayDxp Version7.4 Updateupdate_14
LiferayDxp Version7.4 Updateupdate_2
LiferayDxp Version7.4 Updateupdate_3
LiferayDxp Version7.4 Updateupdate_4
LiferayDxp Version7.4 Updateupdate_5
LiferayDxp Version7.4 Updateupdate_6
LiferayDxp Version7.4 Updateupdate_7
LiferayDxp Version7.4 Updateupdate_8
LiferayDxp Version7.4 Updateupdate_9
LiferayLiferay Portal Version >= 7.3.2 < 7.4.3.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.4
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.