cbcvebase.
CVE-2022-26597
published 2022-04-25

CVE-2022-26597: Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.

Affected

3 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform< 7.37.3
liferaydigital_experience_platform
liferayliferay_portal7.3.0 – 7.4.0