CVE-2022-28980: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Fragment Renderer Collection Filter Implementation before v1.0.11 from Liferay Portal (v7.4.3.4) and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter prefix.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter prefix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.3.5-ga5 - Upgrade
Upgrade
maven/com.liferay:com.liferay.fragment.renderer.collection.filter.implto a version that resolves this vulnerability.Fixed in 1.0.11 - Upgrade
Upgrade
Liferay Fragment Renderer Collection Filter Implementationto a version that resolves this vulnerability.Fixed in 1.0.11 - Upgrade
Upgrade
Liferay Portal (v7.4.3.4) / Liferay DXP v7.4 GAto a version that resolves this vulnerability.Fixed in v7.4.3.4
Event History
Frequently Asked Questions
What is CVE-2022-28980?
CVE-2022-28980 is a vulnerability in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA that allows attackers to execute arbitrary web scripts or HTML through cross-site scripting (XSS) attacks.
What is the severity of CVE-2022-28980?
The severity of CVE-2022-28980 is medium, with a CVSS score of 6.1.
How does CVE-2022-28980 affect Liferay Portal and Liferay DXP?
CVE-2022-28980 affects Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA, allowing attackers to exploit cross-site scripting vulnerabilities through parameters with the filter_ prefix.
How can an attacker exploit CVE-2022-28980?
An attacker can exploit CVE-2022-28980 by injecting malicious web scripts or HTML through parameters with the filter_ prefix, potentially leading to the execution of arbitrary code on vulnerable Liferay Portals or Liferay DXP instances.
Is there a fix available for CVE-2022-28980?
Yes, the fix for CVE-2022-28980 is available in Liferay Portal v7.4.3.5 and later versions, and in Liferay DXP v7.4 FP18 and later versions.