PT-2022-19339 · Liferay · Liferay Portal+1
Published
2022-09-21
·
Updated
2025-05-27
·
CVE-2022-28979
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.1.0 through 7.4.2
Liferay DXP 7.1 before fix pack 26
Liferay DXP 7.2 before fix pack 15
Liferay DXP 7.3 before service pack 3
Description
A cross-site scripting (XSS) issue was discovered in the Portal Search module's Custom Facet widget. This issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the
Custom Parameter Name text field.Recommendations
For Liferay Portal versions 7.1.0 through 7.4.2, update to a version that includes the fix for this issue.
For Liferay DXP 7.1, apply fix pack 26 or later.
For Liferay DXP 7.2, apply fix pack 15 or later.
For Liferay DXP 7.3, apply service pack 3 or later.
As a temporary workaround, consider restricting access to the Custom Facet widget in the Portal Search module until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal