5.4
CVSSv3

CVE-2022-42115

Published: 18/10/2022 Updated: 20/10/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 up to and including 7.4.3.36 allows remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay liferay portal