CVE-2022-42115: XSS
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Object Web before 1.0.99 from Liferay Portal (7.4.3.4 through 7.4.3.36) allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's Label text field.
Other sources
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's Label text field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.object.webto a version that resolves this vulnerability.Fixed in 1.0.99
Event History
Frequently Asked Questions
What is the title of CVE-2022-42115?
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal.
What is the description of CVE-2022-42115?
A cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's Label text field.
What is the severity of CVE-2022-42115?
The severity of CVE-2022-42115 is medium with a score of 5.4.
Which software is affected by CVE-2022-42115?
Liferay Portal versions 7.4.3.4 through 7.4.3.36 are affected by CVE-2022-42115.
How can an attacker exploit CVE-2022-42115?
An attacker can exploit CVE-2022-42115 by injecting a crafted payload into the object field's Label text field, allowing them to inject arbitrary web script or HTML.