CVE-2022-38902: XSS
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38902?
CVE-2022-38902 is a Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3.
How does CVE-2022-38902 affect Liferay DXP?
CVE-2022-38902 affects Liferay DXP 7.3 versions up to 7.3 SP3.
What is the severity of CVE-2022-38902?
CVE-2022-38902 has a severity rating of medium with a score of 5.4 (CVSS v3.1).
How can remote attackers exploit CVE-2022-38902?
Remote attackers can exploit CVE-2022-38902 by injecting arbitrary JavaScript or HTML into the name field of a newly created topic in the Blog module.
Are there any references available for CVE-2022-38902?
Yes, you can find references for CVE-2022-38902 at the following links: [Link 1](http://liferay.com), [Link 2](https://drive.proton.me/urls/D27RQ14NGW#b71d8XrBl2Mu), [Link 3](https://www.offensity.com/en/blog/authenticated-persistent-xss-in-liferay-dxp-cms-cve-2022-38901-and-cve-2022-38902/).