5.4

CVE-2022-42119

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal Version >= 7.3.5 <= 7.4.2
Liferay ≫ Dxp Version 7.3 Update -
Liferay ≫ Dxp Version 7.3 Update update_1
Liferay ≫ Dxp Version 7.3 Update update_2
Liferay ≫ Dxp Version 7.3 Update update_3
Liferay ≫ Dxp Version 7.3 Update update_4
Liferay ≫ Dxp Version 7.3 Update update_5
Liferay ≫ Dxp Version 7.3 Update update_6
Liferay ≫ Dxp Version 7.3 Update update_7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA-ADP 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://issues.liferay.com/browse/LPE-17632
Vendor Advisory
Issue Tracking
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119
Vendor Advisory