CVE-2022-42111: XSS
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42111?
The severity of CVE-2022-42111 is medium with a CVSS score of 5.4.
How does CVE-2022-42111 affect Liferay Portal and Liferay DXP?
CVE-2022-42111 affects Liferay Portal versions 7.2.1 through 7.4.2 and Liferay DXP versions 7.2 before fix pack 19 and 7.3 before update 4.
How can remote attackers exploit CVE-2022-42111?
Remote attackers can exploit CVE-2022-42111 by sharing an asset with a crafted payload to inject arbitrary web script or HTML.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-42111?
The Common Weakness Enumeration (CWE) ID for CVE-2022-42111 is CWE-79.
How can I fix CVE-2022-42111?
To fix CVE-2022-42111, update to Liferay Portal version 7.4.3 or higher, and Liferay DXP version 7.2 fix pack 19 or higher, or version 7.3 update 4 or higher.