8.8

CVE-2022-42121

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.

Data is provided by the National Vulnerability Database (NVD)
LiferayLiferay Portal Version >= 7.1.3 <= 7.4.3.4
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_1
LiferayDigital Experience Platform Version7.1 Updatefix_pack_10
LiferayDigital Experience Platform Version7.1 Updatefix_pack_11
LiferayDigital Experience Platform Version7.1 Updatefix_pack_12
LiferayDigital Experience Platform Version7.1 Updatefix_pack_13
LiferayDigital Experience Platform Version7.1 Updatefix_pack_14
LiferayDigital Experience Platform Version7.1 Updatefix_pack_15
LiferayDigital Experience Platform Version7.1 Updatefix_pack_16
LiferayDigital Experience Platform Version7.1 Updatefix_pack_17
LiferayDigital Experience Platform Version7.1 Updatefix_pack_18
LiferayDigital Experience Platform Version7.1 Updatefix_pack_19
LiferayDigital Experience Platform Version7.1 Updatefix_pack_2
LiferayDigital Experience Platform Version7.1 Updatefix_pack_20
LiferayDigital Experience Platform Version7.1 Updatefix_pack_21
LiferayDigital Experience Platform Version7.1 Updatefix_pack_22
LiferayDigital Experience Platform Version7.1 Updatefix_pack_23
LiferayDigital Experience Platform Version7.1 Updatefix_pack_24
LiferayDigital Experience Platform Version7.1 Updatefix_pack_25
LiferayDigital Experience Platform Version7.1 Updatefix_pack_3
LiferayDigital Experience Platform Version7.1 Updatefix_pack_4
LiferayDigital Experience Platform Version7.1 Updatefix_pack_5
LiferayDigital Experience Platform Version7.1 Updatefix_pack_6
LiferayDigital Experience Platform Version7.1 Updatefix_pack_7
LiferayDigital Experience Platform Version7.1 Updatefix_pack_8
LiferayDigital Experience Platform Version7.1 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_12
LiferayDigital Experience Platform Version7.2 Updatefix_pack_13
LiferayDigital Experience Platform Version7.2 Updatefix_pack_14
LiferayDigital Experience Platform Version7.2 Updatefix_pack_15
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDxp Version7.3 Update-
LiferayDxp Version7.3 Updatesp1
LiferayDxp Version7.3 Updatesp2
LiferayDxp Version7.4 Updatega1
LiferayLiferay Portal Version >= 7.1.0 <= 7.4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.46% 0.633
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.