CVE-2022-42119Cross-site Scripting in Portal

Severity
5.4MEDIUMNVD
EPSS
0.6%
top 29.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15

Description

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDliferay/liferay_portal7.3.57.4.2
NVDliferay/dxp7.3

🔴Vulnerability Details

3
CVEList
CVE-2022-42119: Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module2022-11-15
GHSA
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module2022-11-15
OSV
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module2022-11-15
CVE-2022-42119 — Cross-site Scripting in Liferay Portal | cvebase