CVE-2022-42110Cross-site Scripting in Portal

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 35.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDliferay/liferay_portal7.1.07.4.2
NVDliferay/dxp7.3

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module2022-11-15
GHSA
Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module2022-11-15
CVEList
CVE-2022-42110: A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 72022-11-14
CVE-2022-42110 — Cross-site Scripting in Liferay Portal | cvebase