CVE-2022-42119: XSS
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liferay DXPto a version that resolves this vulnerability.Fixed in 8
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42119?
The severity of CVE-2022-42119 is medium with a score of 5.4.
Which Liferay products are affected by CVE-2022-42119?
CVE-2022-42119 affects Liferay Portal versions 7.3.5 through 7.4.2 and Liferay DXP version 7.3 before update 8.
What is the vulnerability type of CVE-2022-42119?
CVE-2022-42119 is a Cross Site Scripting (XSS) vulnerability.
How can I fix CVE-2022-42119?
To fix CVE-2022-42119, it is recommended to update your Liferay Portal or Liferay DXP to the latest version available.
Where can I find more information about CVE-2022-42119?
You can find more information about CVE-2022-42119 on the official Liferay website, the Liferay issue tracker, and the Liferay developer portal.