CVE-2022-28982: XSS
A cross-site scripting (XSS) vulnerability in Liferay Asset Taglib before v6.1.9 from Liferay Portal (v7.3.3 through v7.4.2) and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
Other sources
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.asset.taglibto a version that resolves this vulnerability.Fixed in 6.1.9
Event History
Frequently Asked Questions
What is CVE-2022-28982?
CVE-2022-28982 is a cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP that allows attackers to execute arbitrary web scripts or HTML.
How does CVE-2022-28982 impact Liferay Portal and Liferay DXP versions?
CVE-2022-28982 impacts Liferay Portal versions 7.3.3 through 7.4.2 and Liferay DXP versions 7.3 before service pack 3.
What is the severity of CVE-2022-28982?
The severity of CVE-2022-28982 is 6.1 (Medium).
How can an attacker exploit CVE-2022-28982?
An attacker can exploit CVE-2022-28982 by injecting a crafted payload into the name of a tag, allowing them to execute arbitrary web scripts or HTML.
Are there any references for CVE-2022-28982?
Yes, you can find references for CVE-2022-28982 at the following links: [http://liferay.com](http://liferay.com) and [https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28982-reflected-xss-with-tag-name-in-%253Cliferay-asset-asset-tags-selector%253E](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28982-reflected-xss-with-tag-name-in-%253Cliferay-asset-asset-tags-selector%253E).