CVE-2022-26593: XSS
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector before 6.1.0 in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of an asset category.
Other sources
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp3 - Upgrade
Upgrade
maven/com.liferay:com.liferay.asset.taglibto a version that resolves this vulnerability.Fixed in 6.1.0
Event History
Frequently Asked Questions
What is CVE-2022-26593?
CVE-2022-26593 is a cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal and Liferay DXP.
What is the severity of CVE-2022-26593?
The severity of CVE-2022-26593 is medium, with a CVSS score of 5.4.
How does CVE-2022-26593 impact Liferay Digital Experience Platform?
CVE-2022-26593 affects Liferay Digital Experience Platform 7.3 and earlier versions.
How does CVE-2022-26593 impact Liferay Portal?
CVE-2022-26593 affects Liferay Portal 7.3.3 through 7.3.7 and Liferay Portal 7.4.0.
How can I fix CVE-2022-26593?
To fix CVE-2022-26593, users should apply the necessary patches or updates provided by Liferay.