CVE-2022-42116: XSS
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Frontend Editor CKEditor Web before 5.0.46 from Liferay Portal (7.3.2 through 7.4.3.14), and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
Other sources
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u15 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u6 - Upgrade
Upgrade
maven/com.liferay:com.liferay.frontend.editor.ckeditor.webto a version that resolves this vulnerability.Fixed in 5.0.46 - Upgrade
Upgrade
Liferay Frontend Editor CKEditor Web (Frontend Editor module - integration with CKEditor)to a version that resolves this vulnerability.Fixed in 5.0.46
Event History
Frequently Asked Questions
What is CVE-2022-42116?
CVE-2022-42116 is a Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15.
What is the severity of CVE-2022-42116?
The severity of CVE-2022-42116 is medium with a CVSS score of 6.1.
How does CVE-2022-42116 work?
CVE-2022-42116 allows remote attackers to inject arbitrary web script or HTML through the 'name' or 'namespace' parameter in the Frontend Editor module.
Which software versions are affected by CVE-2022-42116?
Liferay Portal 7.3.2 through 7.4.3.14 and Liferay DXP 7.3 before update 6 and 7.4 before update 15 are affected by CVE-2022-42116.
How can I fix CVE-2022-42116?
To fix CVE-2022-42116, it is recommended to update to the latest version of Liferay Portal or Liferay DXP that includes the necessary security patches.