CVE-2022-42118: XSS
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liferay Portal (Portal Search module)to a version that resolves this vulnerability.Fixed in 7.4.2 - Upgrade
Upgrade
Liferay Portal 7.1to a version that resolves this vulnerability.Patch fix pack 27 - Upgrade
Upgrade
Liferay Portal 7.2to a version that resolves this vulnerability.Patch fix pack 15 - Upgrade
Upgrade
Liferay Portal 7.3to a version that resolves this vulnerability.Patch service pack 3
Event History
Frequently Asked Questions
What is CVE-2022-42118?
CVE-2022-42118 is a Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 that allows remote attackers to inject arbitrary web script or HTML via the tag parameter.
Which software versions are affected by CVE-2022-42118?
CVE-2022-42118 affects Liferay Portal versions 7.1.0 through 7.4.2 and Liferay DXP versions 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3.
What is the severity of CVE-2022-42118?
The severity of CVE-2022-42118 is medium, with a CVSS score of 6.1.
How can I fix CVE-2022-42118?
To fix CVE-2022-42118, upgrade Liferay Portal to version 7.4.3 or later, and Liferay DXP to version 7.1 fix pack 27 or later, 7.2 fix pack 15 or later, or 7.3 service pack 3 or later.
Where can I find more information about CVE-2022-42118?
You can find more information about CVE-2022-42118 on the Liferay website, the Liferay issue tracker, and the Liferay security vulnerabilities page.