6.1
CVSSv3

CVE-2022-28982

Published: 22/09/2022 Updated: 23/09/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay dxp 7.3

liferay liferay portal