CVE-2022-42110: XSS
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liferay Portal/DEXP Announcements moduleto a version that resolves this vulnerability.Fixed in 7.1.0 through 7.4.2
Event History
Frequently Asked Questions
What is CVE-2022-42110?
CVE-2022-42110 is a Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.
How severe is CVE-2022-42110?
CVE-2022-42110 has a severity level of medium with a CVSS score of 6.1.
What is affected by CVE-2022-42110?
CVE-2022-42110 affects Liferay Portal versions 7.1.0 through 7.4.2, Liferay DXP versions 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.
How can remote attackers exploit CVE-2022-42110?
Remote attackers can exploit CVE-2022-42110 by injecting arbitrary web script or HTML using a Cross-site scripting (XSS) attack on the Announcements module in Liferay Portal and Liferay DXP.
Are there any fixes available for CVE-2022-42110?
Yes, fixes are available for CVE-2022-42110. For Liferay Portal, upgrade to version 7.4.3 or apply the necessary fix pack. For Liferay DXP, upgrade to the corresponding fix pack or service pack depending on the version.