PT-2022-26258 · Liferay · Liferay Portal+1
Published
2022-10-18
·
Updated
2022-10-20
·
CVE-2022-42113
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.3.30 through 7.4.3.36
Liferay DXP 7.4 update 30 through update 36
Description
A Cross-site scripting (XSS) issue in the Document Library module allows remote attackers to inject arbitrary web script or HTML via the
redirect parameter. This could potentially lead to unauthorized actions on the affected system.Recommendations
For Liferay Portal versions 7.4.3.30 through 7.4.3.36, avoid using the
redirect parameter in the Document Library module until a patch is available.
For Liferay DXP 7.4 update 30 through update 36, restrict access to the Document Library module to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal