First published: Tue Nov 15 2022(Updated: )
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay DXP | =7.3 | |
Liferay DXP | =7.4 | |
Liferay Liferay Portal | >=7.3.3<=7.4.3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2022-42120.
This vulnerability affects Liferay Portal versions 7.3.3 through 7.4.3.16, Liferay DXP versions 7.3 before update 4, and 7.4 before update 17.
The severity of CVE-2022-42120 is critical with a CVSS score of 9.8.
An attacker can exploit this vulnerability by executing arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Yes, you can find more information about CVE-2022-42120 at the following references: [1] http://liferay.com, [2] https://issues.liferay.com/browse/LPE-17513, [3] https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42120