CVE-2022-42113: XSS
A Cross-site scripting (XSS) vulnerability in Document Library module before 6.0.98 from Liferay Portal (7.4.3.30 through 7.4.3.36), and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
Other sources
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u37 - Upgrade
Upgrade
maven/com.liferay:com.liferay.document.library.webto a version that resolves this vulnerability.Fixed in 6.0.98 - Upgrade
Upgrade
Liferay Portal (Document Library module) / Liferay DXP 7.4to a version that resolves this vulnerability.Fixed in 6.0.98 - Configuration
Ensure the `redirect` parameter is not reflected without proper validation/encoding; block or sanitize attempts to inject arbitrary web script or HTML through the `redirect` parameter.
Document Library module (Liferay Portal/Liferay DXP 7.4) redirect parameter handling = disallow/validate user-controlled redirect to prevent injection of arbitrary web script or HTML
Event History
Frequently Asked Questions
What is CVE-2022-42113?
CVE-2022-42113 is a Cross-site scripting (XSS) vulnerability in the Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36 and Liferay DXP 7.4 update 30 through update 36.
What is the severity of CVE-2022-42113?
The severity of CVE-2022-42113 is medium with a score of 6.1.
Which software versions are affected by CVE-2022-42113?
Liferay Portal versions 7.4.3.30 through 7.4.3.36 and Liferay DXP versions 7.4 update 30 through update 36 are affected by CVE-2022-42113.
How can CVE-2022-42113 be exploited?
CVE-2022-42113 can be exploited by remote attackers injecting arbitrary web script or HTML via the `redirect` parameter in the Document Library module.
Is there a fix available for CVE-2022-42113?
Yes, the vulnerability has been fixed in Liferay Portal versions 7.4.3.37 and above, and Liferay DXP versions 7.4 update 37 and above.