PT-2022-19339 · Liferay · Liferay Portal +1

Published

2022-09-21

·

Updated

2025-05-27

·

CVE-2022-28979

CVSS v3.1
6.1
VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Liferay Portal versions 7.1.0 through 7.4.2

Liferay DXP 7.1 before fix pack 26

Liferay DXP 7.2 before fix pack 15

Liferay DXP 7.3 before service pack 3

Description:

A cross-site scripting (XSS) issue was discovered in the Portal Search module's Custom Facet widget. This issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `Custom Parameter Name` text field.

Recommendations:

For Liferay Portal versions 7.1.0 through 7.4.2, update to a version that includes the fix for this issue.

For Liferay DXP 7.1, apply fix pack 26 or later.

For Liferay DXP 7.2, apply fix pack 15 or later.

For Liferay DXP 7.3, apply service pack 3 or later.

As a temporary workaround, consider restricting access to the Custom Facet widget in the Portal Search module until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-28979
GHSA-7R3W-WGGM-PJWF

Affected Products

Liferay Dxp
Liferay Portal