CVE-2022-42119
published 2022-11-15CVE-2022-42119: Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.39%
31.6th percentile
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | liferay_portal | 7.3.5 – 7.4.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Commerce cross site scripting
vuldb·2026-07-07·CVSS 5.4
CVE-2022-42119 [MEDIUM] Liferay Portal/DXP Commerce cross site scripting
A vulnerability categorized as problematic has been discovered in Liferay Portal and DXP. Affected by this issue is some unknown functionality of the component Commerce Module. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2022-42119. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
ghsa·2022-11-15
CVE-2022-42119 [MEDIUM] CWE-79 Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects the Commerce module before 4.0.8 from Liferay Portal (7.3.5 through 7.4.2) and Liferay DXP 7.3 before update 8.
OSV
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
osv·2022-11-15
CVE-2022-42119 [MEDIUM] Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects the Commerce module before 4.0.8 from Liferay Portal (7.3.5 through 7.4.2) and Liferay DXP 7.3 before update 8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17632https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119https://issues.liferay.com/browse/LPE-17632https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119
2022-11-15
Published