Show filters
83 Total Results
Displaying 51-60 of 83
Sort by:
Attacker Value
Unknown
CVE-2022-42111
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
0
Attacker Value
Unknown
CVE-2022-42121
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
0
Attacker Value
Unknown
CVE-2022-42110
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2022-38901
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
0
Attacker Value
Unknown
CVE-2022-42117
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2022-42116
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
0
Attacker Value
Unknown
CVE-2022-42112
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2022-38902
Disclosure Date: October 13, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
0
Attacker Value
Unknown
CVE-2022-28977
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.
0
Attacker Value
Unknown
CVE-2022-39975
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
0