CVE-2022-42112: XSS
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget before 6.0.45 from Liferay Portal (7.2.0 through 7.4.3.24), and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
Other sources
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u25 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u5 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp19 - Upgrade
Upgrade
maven/com.liferay:com.liferay.portal.search.webto a version that resolves this vulnerability.Fixed in 6.0.45 - Upgrade
Upgrade
Liferay Portal (Portal Search module - Sort widget)to a version that resolves this vulnerability.Fixed in 6.0.45 - Upgrade
Upgrade
Liferay Portal 7.2 - Liferay Portal Search module (Sort widget)to a version that resolves this vulnerability.Patch fix pack 19 - Upgrade
Upgrade
Liferay Portal 7.3 - Liferay Portal Search module (Sort widget)to a version that resolves this vulnerability.Patch update 5 - Upgrade
Upgrade
Liferay Portal 7.4 - Liferay Portal Search module (Sort widget)to a version that resolves this vulnerability.Patch update 25
Event History
Frequently Asked Questions
What is CVE-2022-42112?
CVE-2022-42112 is a Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal and Liferay DXP.
How does CVE-2022-42112 impact Liferay Portal and Liferay DXP?
CVE-2022-42112 allows remote attackers to inject arbitrary web script or HTML via a crafted payload, potentially leading to cross-site scripting attacks.
Which versions of Liferay Portal and Liferay DXP are affected by CVE-2022-42112?
Liferay Portal 7.2.0 through 7.4.3.24, Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 are affected by CVE-2022-42112.
How severe is CVE-2022-42112?
CVE-2022-42112 has a severity rating of 5.4, which is considered medium.
Where can I find more information about CVE-2022-42112?
You can find more information about CVE-2022-42112 on the Liferay website and the Liferay DXP security vulnerabilities page.