CVE-2022-26597: XSS
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration before 2.0.4 in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
Other sources
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp3 - Upgrade
Upgrade
maven/com.liferay:com.liferay.layout.seo.webto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-26597.
What is the severity level of CVE-2022-26597?
The severity level of CVE-2022-26597 is medium.
How does CVE-2022-26597 affect Liferay Portal and Liferay DXP?
CVE-2022-26597 affects Liferay Portal 7.3.0 through 7.4.0 and Liferay DXP 7.3 before service pack 3.
What can an attacker do with CVE-2022-26597?
With CVE-2022-26597, remote attackers can inject arbitrary web script or HTML via the site name.
Is there a fix available for CVE-2022-26597?
Yes, a fix is available for CVE-2022-26597. Please refer to the official website of Liferay for more information.