CVE-2022-42110
MEDIUM6.1EPSS 0.47%Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module
Published: 11/15/2022Modified: 8/8/2025
Description
A Cross-site scripting (XSS) vulnerability in the Announcements module before 6.0.11 from Liferay Portal (7.1.0 through 7.4.2), and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
Affected packages (2)
- Maven/com.liferay:com.liferay.announcements.webfrom 0, < 6.0.11
- Maven/com.liferay.portal:release.dxp.bom>= 7.1.0, < 7.1.10.fp27
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-42110
- PATCHhttps://github.com/liferay/liferay-portal
- WEBhttps://github.com/liferay/liferay-portal/commit/99b1c4752cd06e6681d7aa9c3b0f58154f434060
- WEBhttps://issues.liferay.com/browse/LPE-17403
- WEBhttps://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-42110?p_r_p_assetEntryId=121612856&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121612856%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse