6.1
CVSSv3

CVE-2022-28980

Published: 22/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows malicious users to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay liferay portal

liferay dxp 7.4