PT-2022-17949 · Liferay · Liferay Portal+1

Published

2022-04-25

·

Updated

2024-01-31

·

CVE-2022-26596

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.1.0 through 7.3.3 Liferay DXP 7.0 before fix pack 94 Liferay DXP 7.1 before fix pack 19 Liferay DXP 7.2 before fix pack 8
Description A cross-site scripting (XSS) issue exists in the Journal module's web content display configuration page, allowing remote attackers to inject arbitrary web script or HTML via web content template names.
Recommendations For Liferay Portal versions 7.1.0 through 7.3.3, update to a version that includes the fix for this issue. For Liferay DXP 7.0, apply fix pack 94 or later. For Liferay DXP 7.1, apply fix pack 19 or later. For Liferay DXP 7.2, apply fix pack 8 or later. As a temporary workaround, consider restricting access to the Journal module's web content display configuration page until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-LIFERAY-2022-26596
CVE-2022-26596
GHSA-W7F2-6896-6MM2

Affected Products

Liferay Dxp
Liferay Portal