9.8
CVSSv3

CVE-2022-42122

Published: 15/11/2022 Updated: 17/11/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows malicious users to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay liferay portal 7.3.7

liferay dxp 7.3