CVE-2022-42121SQL Injection in Portal

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
0.6%
top 30.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDliferay/liferay_portal7.1.37.4.3.4+1
NVDliferay/dxp7.3, 7.4+1

🔴Vulnerability Details

3
GHSA
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module2022-11-15
OSV
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module2022-11-15
CVEList
CVE-2022-42121: A SQL injection vulnerability in the Layout module in Liferay Portal 72022-11-15
CVE-2022-42121 — SQL Injection in Liferay Portal | cvebase