cbcvebase.
CVE-2022-38901
published 2022-10-19

CVE-2022-38901: A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.

Affected

4 ranges
VendorProductVersion rangeFixed in
liferaydxp
liferaydxp
liferaydxp>= 7.0 < 7.37.3
liferayliferay_portal7.3.5 – 7.4.3.28