CVE-2022-38901: XSS
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38901?
The severity of CVE-2022-38901 is medium with a CVSS score of 5.4.
How does CVE-2022-38901 affect Liferay Digital Experience Platform?
CVE-2022-38901 affects Liferay Digital Experience Platform 7.0 to 7.3.10 SP3.
What is the vulnerability in CVE-2022-38901?
CVE-2022-38901 is a Cross-Site Scripting (XSS) vulnerability in the Document and Media module file upload functionality.
How can remote attackers exploit CVE-2022-38901?
Remote attackers can inject arbitrary JavaScript or HTML into the description field of an uploaded SVG file.
Are there any known fixes for CVE-2022-38901?
Yes, Liferay released updates to address CVE-2022-38901. It is recommended to upgrade to the latest version of Liferay Digital Experience Platform.