CVE-2022-38901
published 2022-10-19CVE-2022-38901: A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3…
medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | >= 7.0 < 7.3 | 7.3 |
| liferay | liferay_portal | 7.3.5 – 7.4.3.28 | — |